Alert: 3 zero-day vulnerabilities in Windows are already being actively exploited
Microsoft has confirmed that BlueHammer, RedSun and UnDefend, three zero-day vulnerabilities in Windows 10 and Windows 11, are being actively exploited by cybercriminals in targeted attacks.
BlueHammer is a kernel vulnerability that allows remote code execution without authentication. RedSun allows privilege escalation up to SYSTEM. Combined, attackers can take full control of the system.
UnDefend is the most dangerous: it silently disables Windows Defender, leaving the system exposed without the user noticing. Microsoft has already released emergency patches.
How to protect yourself
- Update Windows: the patches are in the July 2026 cumulative updates.
- Review all devices in the organization.
- Segment the network to limit exposure.
- Monitor suspicious activity looking for remote execution.
Do not wait for the monthly cycle: apply the emergency patches as soon as possible.






