CISA has updated its Known Exploited Vulnerabilities catalog to flag CVE-2026-33825 (BlueHammer), a high-severity Microsoft Defender local privilege escalation flaw, as actively exploited by ransomware gangs. Originally leaked in April by a researcher known as 'Nightmare Eclipse' along with proof-of-concept code, the vulnerability allows attackers to access the Security Account Manager (SAM) database and escalate to SYSTEM privileges. Microsoft patched it in April 2026 Patch Tuesday, but exploitation as a zero-day was confirmed shortly after. CISA had previously ordered federal agencies to patch by May 7; the new update confirms ransomware actors are now leveraging the flaw.
2.1K Impressions