Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Security Patch Release ×3

BlueHammer Windows privilege escalation and Microsoft remediation

Updated 13.05.2026 16:46
Case score 59
Case score 59 Members 4 Latest activity 13.05.2026 16:46
Active exploitation Public PoC/exploit reported KEV: CISA KEV Patch available
Members 4 First seen 06.04.2026 22:19 Last seen 16.04.2026 23:19 Updated 13.05.2026 16:46

Overview

Public exploit code for **BlueHammer / CVE-2026-33825** turned a Windows local privilege-escalation flaw into an active zero-day risk. The issue can expose the **SAM** database and let a local attacker reach **SYSTEM** or elevated administrator access, although the available proof-of-concept was not reliable in every environment. Microsoft has since patched the flaw in the April 2026 updates, including the **Defender Antimalware Platform update 4.18.26050.3011**. CISA also added the CVE to the Known Exploited Vulnerabilities list and set a **May 7** deadline for federal civilian agencies.

Signals

10 derived
Impact signals
Exploitation
Exploitation Active exploitation CVSS 9.8 Critical Exploit Public PoC/exploit reported
CVEs/products
CVE
Remediation
Urgency High KEV CISA KEV Remediation Patch available
Threat context
Tooling Actor Chaotic Eclipse
Data exposure
Leak status Publicly Available

Malware context

0 families · 4 tools
Tools
BlueHammer RedSun UnDefend DarkSword

Member happenings

4 related
Vulnerability Windows BlueHammer local public exploit privilege-escalation flaw
Updated 06.04.2026 22:19 Lead Contribution 59
Exploit Public Exploit Data Type Passwords Data Status Publicly Available Patch No Patch

**BlueHammer** is an **unpatched Windows local privilege escalation flaw** now paired with **public exploit code**, creating immediate risk of **SYSTEM** or elevated-admin takeover on affected systems. The weakness is a **TOCTOU** and **path confusion** issue, and it remains a **zero-day** because there is **no official patch**. Local abuse can reach the **SAM database**, exposing password hashes and potentially leading to **complete machine compromise**.

Security Patch Release Microsoft April 2026 Patch Tuesday security update (165 CVEs)
Updated 15.04.2026 00:22 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency High Patch Patch Available

**Microsoft** shipped **April 2026 Patch Tuesday** updates covering **165 CVEs**, including an **actively exploited zero-day** and a **publicly disclosed** flaw, creating immediate remediation pressure across Windows and related products. The bundle matters because multiple patched bugs can enable **remote code execution**, **elevation of privilege**, or **information disclosure**. Microsoft also said **19 vulnerabilities** are more likely to be exploited and need **high-priority attention**. The update spans **SharePoint Server**, **Defender**, **Windows IKE**, **Word**, and nearly **80 Edge/Chromium fixes**.

Security Patch Release Microsoft April 2026 Patch Tuesday security updates (167 flaws)
Updated 14.04.2026 20:41 Context
Exploitation Active Exploitation CVSS 9.8 Critical Urgency High Patch Patch Available

Microsoft's **April 2026 Patch Tuesday** ships **security updates** for **167 flaws**, including **2 zero-days**, reducing exposure across widely used Microsoft software. The release also fixes **8 Critical vulnerabilities**, including **7 remote code execution** bugs and **1 denial of service** flaw. That scope makes the update bundle especially important for systems running **Microsoft Office**, **SharePoint Server**, and **Microsoft Defender**.

Security Patch Release Microsoft Defender BlueHammer (CVE-2026-33825) Patch Tuesday update
Updated 16.04.2026 23:19 Context
Patch Patch Available

**Microsoft** shipped a **Patch Tuesday** fix for **CVE-2026-33825**, a **Microsoft Defender** local-privilege-escalation flaw that can lead to **SYSTEM** access. The update narrows exposure on affected **Windows 10**, **Windows 11**, and **Windows Server** systems when Defender is enabled. It matters because a released exploit showed the issue was already actionable before the fix landed.