Microsoft Defender Insufficient Granularity of Access Control Vulnerability (CVE-2026-33825).

Release Date: 22nd April 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2026-33825 is a high-severity vulnerability (CVSS ~8.6) in VMware vCenter Server. The flaw is caused by improper input validation (CWE-20) within specific API endpoints exposed by vCenter.

 

References

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2026-33825
  3. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33825