Microsoft Defender Zero-Day “BlueHammer” Hits KEV Catalog Following Researcher’s Protest
ID: 39965659-7587-53da-8b14-3a4d0366e155
STIX ID: report--39965659-7587-53da-8b14-3a4d0366e155
Feed Name: securityonline.info
CISA added CVE-2026-33825 (BlueHammer) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; the flaw in Microsoft Defender leverages TOCTOU and path confusion to obtain SAM password hashes and escalate to SYSTEM. A researcher released PoC code and Huntress Labs observed BlueHammer, RedSun, and UnDefend used in hands-on-keyboard attacks that begin from compromised SSL VPN credentials; Microsoft patched BlueHammer in April 2026 and CISA required FCEB remediation by May 6, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
