CISA confirmed ransomware gangs are exploiting the BlueHammer Microsoft Defender privilege escalation vulnerability, CVE-2026-33825, previously abused in zero-day attacks. The KEV Catalog update highlights continued danger to federal networks and the urgency of patching.

This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
From there, adversaries can raise their rights to SYSTEM level and potentially seize full control of the targeted machine.
Security teams should treat BlueHammer as an active ransomware vector and verify patching across all Windows endpoints, given CISA's explicit ransomware attribution.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
CVE-2026-100841 affects every release of the MONAI medical imaging AI framework through 1.6.0. A local user who can write to a shared cache directory can plant a malicious pickle file that runs code in another user's pipeline. It is rated high severity and no stable fix has shipped.
CVE-2026-100740 is an out-of-bounds write in the L2TP code of the D-Link DIR-895L router on firmware A1_102b07. It can be triggered remotely, scores 8.6 (high), and an exploit is public.
NVD published two more high-severity CVE records for IBM Guardium Data Protection 12.2 on September 25: CVE-2026-85542 (CVSS 8.8), a command injection bug, and CVE-2026-85029 (CVSS 7.5), a path traversal flaw. IBM lists fix pack SqlGuard_12.0p233.
Microsoft Office Outlook has an integer overflow flaw, CVE-2026-100208, that could let an unauthorized attacker run code over a network. Microsoft scores it 7.5 (High), and an attack needs user interaction.
CVE-2026-93306, published by NVD on September 25, lets an unauthenticated attacker on the management network crash the ASMI web server in IBM server firmware with a malformed HTTPS request. IBM rates it 7.1 (High) and has released fixed firmware for Power11, Power10 and Power9 systems.