logo

Microsoft Defender Zero-Day “BlueHammer” Hits KEV Catalog Following Researcher’s Protest

ID: 39965659-7587-53da-8b14-3a4d0366e155

STIX ID: report--39965659-7587-53da-8b14-3a4d0366e155

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Ddos

...
...

CISA added CVE-2026-33825 (BlueHammer) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation; the flaw in Microsoft Defender leverages TOCTOU and path confusion to obtain SAM password hashes and escalate to SYSTEM. A researcher released PoC code and Huntress Labs observed BlueHammer, RedSun, and UnDefend used in hands-on-keyboard attacks that begin from compromised SSL VPN credentials; Microsoft patched BlueHammer in April 2026 and CISA required FCEB remediation by May 6, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.