logo

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

ID: 9b208035-e402-50e4-833f-ae618a9f61bf

STIX ID: report--9b208035-e402-50e4-833f-ae618a9f61bf

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Huntress warns that threat actors are actively exploiting three zero-day flaws in Microsoft Defender—BlueHammer (CVE-2026-33825), RedSun, and UnDefend—leading to local privilege escalation and a DoS that can block updates; BlueHammer was patched by Microsoft but RedSun and UnDefend were observed exploited or with PoCs in the wild and remained unpatched at the time of the report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.