CVE-2026-33824

Published Apr 14, 2026

Last updated 22 days ago

Exploit knownCVSS critical 9.8
Jwt
Network
Zero-day
Tunneling protocol
VPN
Msrpc

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-33824 is a double free vulnerability found within the Windows Internet Key Exchange (IKE) Extension. This memory corruption flaw allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability specifically affects the Windows IPsec IKE service, which is responsible for establishing secure VPN connections and managing cryptographic key exchanges. The flaw can be exploited remotely without authentication or user interaction by sending specially crafted UDP packets to ports 500 (IKE) or 4500 (NAT-T IKE) on a vulnerable Windows system. These malicious packets trigger the double free condition during IKE message parsing, potentially leading to heap corruption and ultimately enabling remote code execution.

Description
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Exploit added on
Aug 18, 2026
Exploit action due
Aug 21, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-415

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2026-33824 — Windows IKE Service Extensions, pre-auth double-free RCE Who should care: Windows 10/11/Server with IKEv2 enabled and UDP 500 or 4500 reachable from untrusted networks — VPN gateways first, also RRAS / Always On VPN hosts. Impact: IKE is the handshake

    @YourDailyCVE

    30 Aug 2026

    118 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CISA added four flaws to KEV in a single day on Aug 18: Windows IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), vCenter (CVE-2026-59310), macOS Screen Sharing (CVE-2026-65400). All four were patched before exploitation was confirmed. Patched is not the same as closed.

    @InfosecDotWatch

    29 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️ New Actively-Exploited Vulnerability • CVE-2026-33824 impacts Microsoft IKE Service. • Double free flaw allows remote code execution. • Listed in CISA KEV, not linked to ransomware. Ensure compliance with CISA’s BOD 26-04. Full report: 🔗 https://t.co/KqalXhWL

    @ido_cohen2

    23 Aug 2026

    1653 Impressions

    2 Retweets

    14 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  4. 🎯 Today's top exploit risk: CVE-2026-33824 (Windows) Actively exploited. Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. #KEV #Windows #CyberThreats

    @BytesNora

    23 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. A double free in Windows IKE Extension is an unauthenticated RCE at CVSS 9.8 (CVE-2026-33824). CISA flagged it as actively exploited on Aug 18, patch due Aug 21 — treat any IKE-exposed Windows host as urgent.

    @SystemArch_AI

    23 Aug 2026

    48 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Windowsの脆弱性「CVE-2026-33824」が注目されています。 IKE機能を狙う深刻な問題ですが、2026年4月の更新で修正済みです。Windows Updateをご確認ください。 https://t.co/MByPY1nZt6 #Windows11

    @KimiyoyaN39483

    22 Aug 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-550

    @HOCupdate

    21 Aug 2026

    382 Impressions

    2 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. NOOR Threat Feed Brief Here are the summarized CVEs, prioritized by real-world exploitation risk: 1. **CVE-2026-33824 (High Risk)**: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - allows remote code execution. 2. **CVE-2025-62593 (High

    @noorchronicle

    21 Aug 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 August 20, 2026 Patches: CISA orders patching of 3 critical flaws by August 21. - Microsoft IKE (CVE-2026-33824, CVSS 9.8) - Adobe Commerce (CVE-2026-71362 CVSS 9.8) - SharePoint (CVE-2026-55040, CVSS 9.1) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t.co/86S

    @CERT_UG

    20 Aug 2026

    103 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Four Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824

    @BlackfireLu

    20 Aug 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CVE-2026-33824 Windows IKE 원격 코드 실행 취약점 원인 분석과 패치 방법 https://t.co/1JBZwd9lWF

    @J_zjaan7946

    20 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Windows IKEにおけるRCE脆弱性が悪用される(CVE-2026-33824) | Codebook|Security News https://t.co/ICxA0REjVV

    @ohhara_shiojiri

    20 Aug 2026

    65 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CISA has confirmed active exploitation of CVE-2026-33824, a CVSS 9.8 flaw in the Windows IKE VPN service. Patched April 2026. Unpatched Windows VPN servers reachable on UDP 500 or 4500 are exposed. https://t.co/MDrvGXoVrq https://t.co/MhdrPJ4hA9

    @CyberPulse_aus

    20 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Legacy exposure keeps paying off for attackers. CVE-2026-33824: Windows IKE RCE Active Exploit Patch Guide CVE-2026-33824 Windows IKE RCE is now in CISA KEV after active exploitation. Patch VPN/IPse… 🔗 Read → https://t.co/17tR7PA4DK

    @fynn_JourX

    20 Aug 2026

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🛑 CVE-2026-33824: Windows IKE RCE Active Exploit Patch Guide CVE-2026-33824 Windows IKE RCE is now in CISA KEV after active exploitation. Patch VPN/IPse… 🔗 Details → https://t.co/iLR4i8TsHt

    @lucasverdan

    20 Aug 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. For defenders, cve-2026-33824: windows ike rce active exploit patch guide should move fast. CVE-2026-33824 Windows IKE RCE is now in CISA KEV after active exploitation. Patch VPN/IPse… 🔗 Details → https://t.co/A8LNYpYouF

    @SocXAInvaders

    19 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://t.co/Zs

    @TheHackersNews

    19 Aug 2026

    48061 Impressions

    90 Retweets

    317 Likes

    91 Bookmarks

    4 Replies

    3 Quotes

  18. CyberSignal Daily ✓ · 🚨 Vulnerability Alert · August 19, 2026 🎯 Microsoft, VMware and Apple products all appear in today's exploited-vulnerability warning. CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33824 — Microsoft IK

    @XQOPTRX

    19 Aug 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. 米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/18追加) #vulnerability 🛡CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / Micro

    @piyokango

    19 Aug 2026

    4356 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  20. CISAが既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Aug 18) CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free の脆弱性 CVE-2026-55040 Microsoft SharePoint

    @foxbook

    19 Aug 2026

    278 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🔒 #CyberSecurity CVE-2026-33824: Microsoft IKE Service Extensions Double Free Actively Exploited… "On August 18, 2026, CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/wKvhVGZ4zP #CyberSecurity #ThreatIntel #cve202633824 #critical #c

    @SecurityAr58409

    19 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日

    @__kokumoto

    18 Aug 2026

    634 Impressions

    0 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Microsoft unveiled MDASH, an AI system with 100+ agents that found and proved 16 Windows flaws fixed in Patch Tuesday, including CVE-2026-33824 and CVE-2026-33827. #Microsoft #MDASH #Windows https://t.co/WiMyQUaiY2

    @TweetThreatNews

    13 May 2026

    112 Impressions

    0 Retweets

    0 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  24. #exploit #NetSec 1⃣. CVE-2026-33824: RCE in Windows IKEv2 https://t.co/IdbRP0IExo // The flaw involves improper handling of a blob pointer during IKEv2 fragment reassembly, causing a double free when cleaning up security structures 2⃣. CVE-2025-57738: Apache Syncope Groovy

    @ksg93rd

    24 Apr 2026

    230 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations