CISA: Windows BlueHammer flaw now exploited by ransomware gangs
Reported exploitedMicrosoft Defenderransomware gangsOur summary
The U.S. CISA has confirmed that ransomware groups have started exploiting the Microsoft Defender privilege-escalation vulnerability tracked as CVE-2026-33825. This issue, known as BlueHammer, allows an authenticated attacker to elevate local privileges by exploiting overly broad access control, which can lead to SYSTEM-level control and full compromise. CISA added CVE-2026-33825 to its KEV catalog and urged rapid patching because it is now tied to real ransomware activity.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.