CVE-2026-33824
Published Apr 14, 2026
Last updated 22 days ago
AI description
CVE-2026-33824 is a double free vulnerability found within the Windows Internet Key Exchange (IKE) Extension. This memory corruption flaw allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability specifically affects the Windows IPsec IKE service, which is responsible for establishing secure VPN connections and managing cryptographic key exchanges. The flaw can be exploited remotely without authentication or user interaction by sending specially crafted UDP packets to ports 500 (IKE) or 4500 (NAT-T IKE) on a vulnerable Windows system. These malicious packets trigger the double free condition during IKE message parsing, potentially leading to heap corruption and ultimately enabling remote code execution.
- Description
- Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
- Exploit added on
- Aug 18, 2026
- Exploit action due
- Aug 21, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- secure@microsoft.com
- CWE-415
- Hype score
- Not currently trending
🚨 CVE-2026-33824 — Windows IKE Service Extensions, pre-auth double-free RCE Who should care: Windows 10/11/Server with IKEv2 enabled and UDP 500 or 4500 reachable from untrusted networks — VPN gateways first, also RRAS / Always On VPN hosts. Impact: IKE is the handshake
@YourDailyCVE
30 Aug 2026
118 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
CISA added four flaws to KEV in a single day on Aug 18: Windows IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), vCenter (CVE-2026-59310), macOS Screen Sharing (CVE-2026-65400). All four were patched before exploitation was confirmed. Patched is not the same as closed.
@InfosecDotWatch
29 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ New Actively-Exploited Vulnerability • CVE-2026-33824 impacts Microsoft IKE Service. • Double free flaw allows remote code execution. • Listed in CISA KEV, not linked to ransomware. Ensure compliance with CISA’s BOD 26-04. Full report: 🔗 https://t.co/KqalXhWL
@ido_cohen2
23 Aug 2026
1653 Impressions
2 Retweets
14 Likes
3 Bookmarks
0 Replies
0 Quotes
🎯 Today's top exploit risk: CVE-2026-33824 (Windows) Actively exploited. Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. #KEV #Windows #CyberThreats
@BytesNora
23 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A double free in Windows IKE Extension is an unauthenticated RCE at CVSS 9.8 (CVE-2026-33824). CISA flagged it as actively exploited on Aug 18, patch due Aug 21 — treat any IKE-exposed Windows host as urgent.
@SystemArch_AI
23 Aug 2026
48 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windowsの脆弱性「CVE-2026-33824」が注目されています。 IKE機能を狙う深刻な問題ですが、2026年4月の更新で修正済みです。Windows Updateをご確認ください。 https://t.co/MByPY1nZt6 #Windows11
@KimiyoyaN39483
22 Aug 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-550
@HOCupdate
21 Aug 2026
382 Impressions
2 Retweets
2 Likes
1 Bookmark
0 Replies
0 Quotes
NOOR Threat Feed Brief Here are the summarized CVEs, prioritized by real-world exploitation risk: 1. **CVE-2026-33824 (High Risk)**: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - allows remote code execution. 2. **CVE-2025-62593 (High
@noorchronicle
21 Aug 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 August 20, 2026 Patches: CISA orders patching of 3 critical flaws by August 21. - Microsoft IKE (CVE-2026-33824, CVSS 9.8) - Adobe Commerce (CVE-2026-71362 CVSS 9.8) - SharePoint (CVE-2026-55040, CVSS 9.1) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t.co/86S
@CERT_UG
20 Aug 2026
103 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Four Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824
@BlackfireLu
20 Aug 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-33824 Windows IKE 원격 코드 실행 취약점 원인 분석과 패치 방법 https://t.co/1JBZwd9lWF
@J_zjaan7946
20 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Windows IKEにおけるRCE脆弱性が悪用される(CVE-2026-33824) | Codebook|Security News https://t.co/ICxA0REjVV
@ohhara_shiojiri
20 Aug 2026
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA has confirmed active exploitation of CVE-2026-33824, a CVSS 9.8 flaw in the Windows IKE VPN service. Patched April 2026. Unpatched Windows VPN servers reachable on UDP 500 or 4500 are exposed. https://t.co/MDrvGXoVrq https://t.co/MhdrPJ4hA9
@CyberPulse_aus
20 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Legacy exposure keeps paying off for attackers. CVE-2026-33824: Windows IKE RCE Active Exploit Patch Guide CVE-2026-33824 Windows IKE RCE is now in CISA KEV after active exploitation. Patch VPN/IPse… 🔗 Read → https://t.co/17tR7PA4DK
@fynn_JourX
20 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 CVE-2026-33824: Windows IKE RCE Active Exploit Patch Guide CVE-2026-33824 Windows IKE RCE is now in CISA KEV after active exploitation. Patch VPN/IPse… 🔗 Details → https://t.co/iLR4i8TsHt
@lucasverdan
20 Aug 2026
66 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, cve-2026-33824: windows ike rce active exploit patch guide should move fast. CVE-2026-33824 Windows IKE RCE is now in CISA KEV after active exploitation. Patch VPN/IPse… 🔗 Details → https://t.co/A8LNYpYouF
@SocXAInvaders
19 Aug 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://t.co/Zs
@TheHackersNews
19 Aug 2026
48061 Impressions
90 Retweets
317 Likes
91 Bookmarks
4 Replies
3 Quotes
CyberSignal Daily ✓ · 🚨 Vulnerability Alert · August 19, 2026 🎯 Microsoft, VMware and Apple products all appear in today's exploited-vulnerability warning. CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33824 — Microsoft IK
@XQOPTRX
19 Aug 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/18追加) #vulnerability 🛡CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / Micro
@piyokango
19 Aug 2026
4356 Impressions
0 Retweets
3 Likes
1 Bookmark
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性4件をカタログに追加 CISA Adds Four Known Exploited Vulnerabilities to Catalog #CISA (Aug 18) CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free の脆弱性 CVE-2026-55040 Microsoft SharePoint
@foxbook
19 Aug 2026
278 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-33824: Microsoft IKE Service Extensions Double Free Actively Exploited… "On August 18, 2026, CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities…" 🔗 https://t.co/wKvhVGZ4zP #CyberSecurity #ThreatIntel #cve202633824 #critical #c
@SecurityAr58409
19 Aug 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日
@__kokumoto
18 Aug 2026
634 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft unveiled MDASH, an AI system with 100+ agents that found and proved 16 Windows flaws fixed in Patch Tuesday, including CVE-2026-33824 and CVE-2026-33827. #Microsoft #MDASH #Windows https://t.co/WiMyQUaiY2
@TweetThreatNews
13 May 2026
112 Impressions
0 Retweets
0 Likes
2 Bookmarks
0 Replies
0 Quotes
#exploit #NetSec 1⃣. CVE-2026-33824: RCE in Windows IKEv2 https://t.co/IdbRP0IExo // The flaw involves improper handling of a blob pointer during IKEv2 fragment reassembly, causing a double free when cleaning up security structures 2⃣. CVE-2025-57738: Apache Syncope Groovy
@ksg93rd
24 Apr 2026
230 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "158C16A3-547E-4130-8428-8E429C37E573",
"versionEndExcluding": "10.0.14393.9060",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "58E1A340-D49A-4EBB-A750-876922ACD5CA",
"versionEndExcluding": "10.0.14393.9060",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "64248504-2307-45FC-8FF3-7A227CFD8675",
"versionEndExcluding": "10.0.17763.8644",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "9B1465B1-BDE6-4634-8F12-43F71D68A4D6",
"versionEndExcluding": "10.0.17763.8644",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "88A175C4-E033-4FE7-B2BF-8BAE14321BC4",
"versionEndExcluding": "10.0.19044.7184",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "86DBF14A-F486-4FE7-9126-D1D54952FC6C",
"versionEndExcluding": "10.0.19044.7184",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "C375372B-D3D4-4B11-AAD8-69AC344C24BC",
"versionEndExcluding": "10.0.19044.7184",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "8CE2E268-E776-4697-9E43-33ABA4CDBE05",
"versionEndExcluding": "10.0.19045.7184",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "269B8E88-6473-41DD-BA33-D9184B82CA58",
"versionEndExcluding": "10.0.19045.7184",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "FCBB431B-EF21-4454-BDA3-D8F276BE7A64",
"versionEndExcluding": "10.0.19045.7184",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "B33CE091-B873-4C30-BA05-54A8C1839212",
"versionEndExcluding": "10.0.22631.6936",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "E3AF28F3-D486-4B88-9E0E-371241024174",
"versionEndExcluding": "10.0.22631.6936",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "94EB36C7-1FF2-4B44-AD91-F3540F09393E",
"versionEndExcluding": "10.0.26100.8246",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "14B23C3F-C8AC-491A-BCA5-EB6982C8F9E9",
"versionEndExcluding": "10.0.26100.8246",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "361B5DAB-8D1F-45D7-A33C-F49EBA56B5F8",
"versionEndExcluding": "10.0.26200.8246",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "ADC6CE99-AB5D-4DD5-82A9-892366C4B2FD",
"versionEndExcluding": "10.0.26200.8246",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
"matchCriteriaId": "690E74A8-E72C-47B6-96EB-37C48D69A635",
"versionEndExcluding": "10.0.28000.1836",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "13A01FA1-08DC-4E33-9FFC-AB4BCD9634CA",
"versionEndExcluding": "10.0.28000.1836",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "982DB0CA-5196-4E42-B2F7-994BE8179715",
"versionEndExcluding": "10.0.14393.9060",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "647CF9B5-8898-469B-9C09-D372A7843187",
"versionEndExcluding": "10.0.17763.8644",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DC6837B7-5DFD-4AF7-B436-3C6FEF48BA60",
"versionEndExcluding": "10.0.20348.5020",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "55A1F3AB-5299-4495-9A73-FDA23C6FD88D",
"versionEndExcluding": "10.0.25398.2274",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "ADF41A14-B9DA-4788-82A8-74DCDCD090E1",
"versionEndExcluding": "10.0.26100.32690",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]