← Back to CVE intelligence
CVE intelligenceCISA KEVRansomware use

CVE-2026-33825

Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Published Apr 14, 2026Sources checked Sep 27, 2026
7.8HIGHCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2026-33825 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Microsoft Defender.

  • Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA KEVListedObserved exploitation
EPSS0.4%Estimated 30-day exploitation probability
Ransomware useReported by CISACISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-33825?

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.