Microsoft Defender Zero-Days Leaked: 'BlueHammer' Exploit Targets Unpatched Windows Flaws

Post date: April 17, 2026 · Discovered: April 18, 2026 · 3 posts, 0 comments

At least three Microsoft Defender zero-days are reportedly active in the wild, with multiple vulnerabilities remaining unpatched. Specific leaks include 'BlueHammer,' an exploit targeting an unpatched Windows privilege escalation flaw that can grant SYSTEM or elevated administrator permissions.

Users are focused on researcher claims detailing multiple vulnerabilities. According to monica_b1998, the issue involves three actively exploited zero-days in Microsoft Defender. Further inputs name 'RedSun' and 'UnDefend' as additional zero-days, one allowing standard users to block Defender updates, reported by lemmydev2.

The weight of discussion centers on immediate, high-severity risk. The consensus is that multiple critical, unpatched flaws exist in Windows and Defender, enabling direct, high-level system compromise.

Key Points

SUPPORT

BlueHammer exploit targets Windows privilege escalation.

lemmydev2 detailed the leaked exploit targeting an unpatched flaw granting SYSTEM permissions.

SUPPORT

Three Microsoft Defender zero-days are actively exploited.

monica_b1998 flagged the existence of three zero-days currently being weaponized.

SUPPORT

Existence of 'RedSun' and 'UnDefend' zero-days.

lemmydev2 named two more researcher-released flaws, specifically 'RedSun' and 'UnDefend'.

SUPPORT

Flaws allow for disabling security measures.

The discussion noted 'UnDefend' allows standard users to disable or block Defender updates.

Source Discussions (3)

This report was synthesized from the following Lemmy discussions, ranked by community score.

71
points
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
[email protected]·0 comments·4/17/2026·by monica_b1998·thehackernews.com
31
points
Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild
[email protected]·0 comments·4/17/2026·by lemmydev2·helpnetsecurity.com
20
points
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
[email protected]·0 comments·4/6/2026·by lemmydev2·bleepingcomputer.com