๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Summary
Microsoft Defender has a vulnerability in access control (the rules that decide what actions a user is allowed to perform) that could let an authorized attacker gain higher-level system permissions on a local computer. The vulnerability is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Details
EPSS: 0.1%
Yes
๐ฅ Actively Exploited
April 21, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33825
First tracked: April 22, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%