Ransomware gangs have started actively exploiting a high-severity Microsoft Defender vulnerability that was previously used in zero-day attacks, according to CISA.
The flaw, tracked as CVE-2026-33825 and dubbed BlueHammer, allows a local attacker to escalate privileges by exploiting insufficient access control in Microsoft Defender. It gives attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts, letting them escalate to SYSTEM and take full control of the machine.
Microsoft patched the vulnerability on April 14 as part of its April Patch Tuesday. But things took a turn when a researcher going by “Nightmare Eclipse” leaked the exploit code in early April, protesting how MSRC handles disclosure. Days later, Huntress Labs found evidence of threat actors exploiting it in the wild.
CISA added BlueHammer to its Known Exploited Vulnerabilities Catalog on April 22, ordering federal civilian agencies to patch within two weeks. The agency warned this type of vulnerability poses significant risks to the federal enterprise.
Nightmare Eclipse has since disclosed multiple other Windows zero-day exploits, including RoguePlanet, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend. Microsoft fixed several of these in June’s Patch Tuesday.
