CISA has confirmed active exploitation of the BlueHammer vulnerability in Microsoft Defender by ransomware gangs, adding it to the Known Exploited Vulnerabilities catalog with a patching deadline. The flaw, a local privilege escalation issue, was leaked in early April 2026 by researcher Nightmare Eclipse along with PoC code as a protest against Microsoft's disclosure handling. It allows authorized attackers to elevate privileges by accessing the SAM database for password hashes and potentially gaining SYSTEM control.
Microsoft described it euphemistically as “insufficient granularity of access control,” which the host criticizes as improper design rather than a minor issue, and patched it in the April 2026 Patch Tuesday. Huntress Labs had already observed zero-day hands-on-keyboard exploitation shortly after. Nightmare Eclipse has disclosed multiple related Windows zero-days affecting Defender, BitLocker, and other components, some of which were fixed in June 2026 updates.
CISA initially added BlueHammer (CVE-2026-33825) to KEV on April 22, mandating federal patches by May 7 due to its frequent use as an attack vector. Microsoft has not yet officially tagged it as exploited, but CISA's update now links it to ransomware campaigns, underscoring ongoing risks from Defender vulnerabilities.