Vulnerability  ·  2026-04-18

Three Microsoft Defender Zero-Days Actively Exploited by Threat Actors

VulnerabilityHigh impactCVE-2026-33825 (BlueHammer only), RedSun and UnDefend unpatched
Three vulnerabilities in Microsoft Defender (codenamed BlueHammer, RedSun, and UnDefend) allow attackers to gain elevated privileges on compromised Windows systems. Published by researcher 'Chaotic Eclipse' as zero-days in response to Microsoft's vulnerability disclosure process.
Exploitation of Windows Defender components to escalate privileges and gain administrator access. Exploit code is publicly available on GitHub.
Microsoft Windows Defender across Windows environments. BlueHammer has been patched, but RedSun and UnDefend remain unpatched.
Apply Microsoft patch for CVE-2026-33825 (BlueHammer) immediately. Monitor for patches for RedSun and UnDefend. Implement additional endpoint monitoring and restrict administrator privileges.
Sources
TechCrunchHuntress Labs
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →