CISA says attackers are exploiting Windows IKE Extension remote-code-execution flaw CVE-2026-33824

CISA says hackers are now exploiting a critical Windows networking flaw that can let an attacker run code on vulnerable systems from across the network. The bug, CVE-2026-33824, is a double-free remote code execution flaw in the Windows Internet Key Exchange Extension (MS-IKEE) affecting supported Windows 10, Windows 11, and Windows Server releases when IKEv2 is enabled; attackers can send crafted packets to UDP ports 500 or 4500. Microsoft patched it in April 2026, and CISA has now added it to the Known Exploited Vulnerabilities catalog.
Why it matters: Organizations running exposed Windows systems with IKE enabled should treat this as urgent because attackers can hit it without logging in. Patch immediately, and if you cannot, restrict or block UDP 500 and 4500 and limit IKE traffic to known peer addresses.

Sources

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
info@thehackernews.com (The Hacker News) 2026.08.19 88% relevant
It likely summarizes the same active exploitation of the Windows IKE Extension flaw and adds broader visibility by placing it alongside other in-the-wild issues defenders should triage.
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
Ionut Arghire 2026.08.19 95% relevant
This article adds that CISA formally urged immediate patching and included CVE-2026-33824 in KEV as part of a four-flaw batch, with an August 21 federal remediation deadline.
Critical RCE flaw in Windows IKE Extension now actively exploited
Sergiu Gatlan 2026.08.19 100% relevant
This article establishes a distinct tracked event: CISA's confirmation that CVE-2026-33824 in Windows IKE Extension is under active exploitation, which materially changes the risk from a patched flaw to an in-the-wild threat.
← Back to all stories