• News/
  • bleepingcomputer-20260630085313

CISA: Windows BlueHammer flaw now exploited by ransomware gangs

BleepingComputer
·
Sergiu Gatlan
·
Published Jun 30, 2026
·
Updated

CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks. Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as "Nightmare Eclipse" in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process. "Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally," Microsoft explains in a security advisory. Will Dormann, principal vulnerability analyst at Tharros, told BleepingComputer in April that while the issue is not easy to exploit, it gives local attackers access to the Security Account Manager (SAM) database, which contains password hashes for local accounts. With this access, they can escalate to SYSTEM privileges and potentially take complete control of the targeted system. “At that point, [the attackers] basically own the system, and can do things like spawn a SYSTEM-privileged shell,” Dormann said. Microsoft patched the vulnerability on April 14 as part of the April 2026 Patch Tuesday. However, days later, Huntress Labs security researchers revealed that threat actors had been exploiting it as a zero-day in attacks that showed evidence of "hands-on-keyboard threat actor activity." Over the past several months, Nightmare Eclipse has disclos...

Read full article

Affected Software

1 affected component
Microsoft Defender=CVE-2026-33825
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the exploitation of a high-severity vulnerability in Microsoft Defender known as BlueHammer by ransomware gangs.

2

What security implications are discussed in the article?

The article highlights that the BlueHammer vulnerability has been abused in zero-day attacks and is now actively exploited by ransomware actors.

3

What products or software are affected by the BlueHammer vulnerability?

The affected software is Microsoft Defender, which is subject to the privilege escalation vulnerability.

4

What is the CVE number associated with the BlueHammer vulnerability?

The CVE number for the BlueHammer vulnerability is CVE-2026-33825.

5

When did CISA confirm the exploitation of the BlueHammer vulnerability?

CISA confirmed the exploitation of the BlueHammer vulnerability on June 30, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203