Microsoft Defender Zero-Days Weaponized After Researcher Leaks Exploit Code

A security researcher’s frustration with Microsoft’s disclosure process has led to three zero-day vulnerabilities in Microsoft Defender being weaponized in the wild, with active exploitation confirmed since April 10, 2026. The situation highlights a growing tension between independent security researchers and vendor response protocols.

The BlueHammer Vulnerability (CVE-2026-33825)

The most critical of the three flaws, BlueHammer is a local privilege escalation (LPE) vulnerability that allows low-privileged users to achieve SYSTEM-level access on fully patched Windows 10 and 11 systems. The exploit leverages a time-of-check to time-of-use (TOCTOU) race condition combined with path confusion in Defender’s signature update mechanism.

Timeline of exploitation:

  • April 10, 2026: First active exploitation detected in the wild
  • April 14, 2026: Microsoft Patch Tuesday addresses the vulnerability
  • April 22, 2026: CISA adds CVE-2026-33825 to Known Exploited Vulnerabilities Catalog
  • May 6, 2026: Deadline for federal agencies to apply patches

The vulnerability carries a CVSS score that reflects its severity, and CISA’s inclusion in the KEV catalog makes patching mandatory for all federal systems.

RedSun and UnDefend: Still Unpatched

While BlueHammer received attention and a patch, two companion vulnerabilities remain in a more dangerous state:

RedSun – Another local privilege escalation flaw impacting Microsoft Defender, observed being exploited since April 16, 2026. Unlike BlueHammer, this vulnerability reportedly remains unpatched as of the latest updates.

UnDefend – A denial-of-service (DoS) vulnerability that can block Defender definition updates entirely. This creates a secondary attack vector: even if systems are patched against other threats, UnDefend can prevent the security updates from being applied in the first place.

The researcher behind these discoveries, operating under the alias “Chaotic Eclipse” (also known as Nightmare-Eclipse), released proof-of-concept exploit code publicly after expressing dissatisfaction with Microsoft’s vulnerability disclosure process. This “responsible disclosure gone wrong” scenario has become increasingly common as researchers grow frustrated with vendor timelines.

The SharePoint Zero-Day (CVE-2026-32201)

Separately, Microsoft SharePoint Server is facing active exploitation of a spoofing vulnerability with a CVSS score of 6.5. This flaw allows unauthorized attackers to view and modify sensitive information without any user interaction required.

What makes this particularly dangerous is the attack surface – SharePoint instances are often internet-facing and contain sensitive organizational data. The vulnerability enables direct data manipulation without needing to compromise user credentials first.

Chrome Zero-Day Under Active Exploitation

Google Chrome users also face an active threat from CVE-2026-5281, a use-after-free vulnerability in Dawn (the open-source WebGPU implementation). This flaw allows remote code execution via crafted HTML pages – meaning simply visiting a malicious website could compromise your system.

Key details:

  • Patch released: April 1, 2026
  • CISA KEV deadline: April 15, 2026 (for federal agencies)
  • Attack vector: Remote, no user interaction beyond visiting a webpage
  • Impact: Arbitrary code execution

What This Means for Your Organization

The convergence of these vulnerabilities creates a perfect storm:

  1. Security software compromised – When the tool meant to protect you becomes the attack vector, traditional defense-in-depth strategies fail
  2. Researcher-vendor tensions escalating – Expect more public disclosures with exploit code as frustration grows
  3. Patch cycles too slow – The gap between discovery, disclosure, patching, and deployment is being weaponized
  4. Federal mandates signal urgency – CISA’s KEV catalog additions indicate these aren’t theoretical risks

Immediate Actions Required

For Windows environments:

  1. Apply April 2026 Patch Tuesday updates immediately (if not already deployed)
  2. Verify Defender is receiving definition updates (check for UnDefend exploitation)
  3. Monitor for privilege escalation attempts, especially from low-privileged accounts
  4. Review SharePoint instances for unauthorized access or modifications

For all browsers:

  1. Update Chrome to the latest version (CVE-2026-5281 patch)
  2. Consider temporary restrictions on WebGPU-enabled sites if exploitation is detected
  3. Monitor network traffic for suspicious code execution patterns

Long-term considerations:

  1. Reevaluate trust boundaries around security software – Defender should not have unchecked system access
  2. Implement application whitelisting to limit what can execute even with SYSTEM privileges
  3. Prepare for more researcher-driven disclosures with exploit code – the traditional disclosure model is fracturing

The Bottom Line

These vulnerabilities represent more than just another Patch Tuesday. They signal a shift in how security research is conducted and disclosed. When researchers feel vendors aren’t responding appropriately, they’re increasingly choosing public disclosure with working exploits over quiet coordination.

For defenders, this means the threat landscape is becoming more volatile. The window between vulnerability discovery and active exploitation is shrinking, and the source of disclosures is becoming less predictable.

Your patch management process can’t wait for monthly cycles anymore. These flaws were being exploited within days of discovery. Speed matters more than ever.

Tzar C. Umang is a technology leader with over 15 years of experience making new technologies work for different industries. As the Chief Technology Officer at Makerspace Innovhub OPC and the Lead Developer for SUI Philippines, he leads projects that create growth and opportunities for everyone. With a strong background in blockchain development, AI engineering, and cybersecurity, Tzar has worked with organizations like the DOST Smarter Philippines Project Management Office and US startup Auto Genie. He is committed to helping the next generation of tech professionals, serving as a cybersecurity instructor at the University of Luzon and a mentor for the Saleng Mentors Group. In his free time, Tzar focuses on building practical solutions for education, healthcare, and new businesses.

Site Footer