CISA has updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-33825 (BlueHammer), a high-severity Microsoft Defender local privilege escalation flaw, as actively exploited by ransomware gangs. Originally leaked in April by a researcher known as 'Nightmare Eclipse' along with proof-of-concept code, the vulnerability allows attackers to access the Security Account Manager (SAM) database and escalate to SYSTEM privileges. Microsoft patched it in April 2026 Patch Tuesday, but exploitation as a zero-day was confirmed shortly after. CISA had previously ordered federal agencies to patch by May 7; the new update confirms ransomware actors are now leveraging the flaw.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Flagged as exploited by ransomware gangsTest every layer before attackers do
2.1K Impressions