CISA puts US government agencies on two-week deadline to patch Microsoft Defender BlueHammer zero-day exploit



  • CISA added BlueHammer, a Microsoft Defender privilege escalation flaw, to its Known Exploited Vulnerabilities catalog.
  • Federal agencies have until May 6 to patch or discontinue use, as researchers confirmed active exploitation in the wild.
  • The disclosure came from “Chaotic Eclipse,” who also revealed two other Defender zero‑days, with Huntress Labs linking exploitation attempts to suspicious global infrastructure.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added BlueHammer to its catalog of known exploited vulnerabilities (KEV), giving Federal Civilian Executive Branch (FCEB) agencies a two-week deadline to patch up or stop using the vulnerable software entirely.

BlueHammer is described as an “insufficient granularity of access control in Microsoft Defender” vulnerability, which allows unauthorized attackers to elevate the privileges locally. It is being tracked as CVE-2026-33825, and was given a severity score of 7.8/10 (high).

https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img