HIGHVulnerability
Verified
Global

CISA KEV: Microsoft Defender — Microsoft Defender Insufficient Granularity of Access Control Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

Analysis

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-22. Remediation due: 2026-05-06.

Indicators of Compromise (1)

CVE (1)
CVE-2026-33825
Source Attribution

Originally published by CISA KEV on Apr 22, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-102240 — A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the ...

A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not res

CVE-2026-102240
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-101354 — A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affecte...

A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must have access to the local network to execute the attack. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab

CVE-2026-101354
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-102361 — mall4j through 4.0 contains a missing authentication vulnerability in the PUT /u...

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

CVE-2026-102361
NIST NVD