logo

CISA orders feds to patch BlueHammer flaw exploited as zero-day

ID: a2b8833d-038e-5c2f-bc0e-e608b39f3eec

STIX ID: report--a2b8833d-038e-5c2f-bc0e-e608b39f3eec

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Sergiu Gatlan

...
...

CISA ordered Federal Civilian Executive Branch agencies to urgently patch a Microsoft Defender privilege-escalation zero-day (CVE-2026-33825, "BlueHammer") after public PoC publication and observed in-the-wild exploitation; Microsoft patched the bug on April 14, and security researchers reported related active intrusions and suspicious VPN access linked to a likely campaign, while additional related Defender flaws ("RedSun", "UnDefend") were disclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.