logo

BlueHammer, RedSun, and UnDefend: Three Windows Defender Zero-Days Exploited in the Wild

ID: d3711ec3-cb41-5da7-b3d5-550f23556507

STIX ID: report--d3711ec3-cb41-5da7-b3d5-550f23556507

Feed Name: SOCRadar Blog

Threat Score
88/100

Date Published: 2026-04-17

Date Updated: 2026-05-11

Author: Ameer Owda

...
...

Three Windows Defender zero-day vulnerabilities—BlueHammer (CVE-2026-33825), RedSun, and UnDefend—were publicly disclosed with proof-of-concept exploits in April 2026; BlueHammer was patched in the April Patch Tuesday, while RedSun and UnDefend remain unpatched and have been observed in the wild, enabling local privilege escalation to SYSTEM and suppression of Defender updates. Organizations are advised to apply available patches, monitor for privilege escalation and remote-access credential compromise, and prepare for additional disclosures or out-of-band fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.