📣 Send us your press release
Site updates every 15 minutes
Technology

Microsoft Windows IKE Vulnerability Confirmed as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical vulnerability in Windows' Internet Key Exchange (IKE) service (CVE-2026-33824) is actively being exploited in network attacks.

22 August 2026
Microsoft Windows IKE Vulnerability Confirmed as Actively Exploited
Image is an AI-generated illustration

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) service extension component to its catalog of known exploited vulnerabilities. CISA has confirmed that the vulnerability, designated CVE-2026-33824, is under active exploitation.

The flaw allows attackers to send specially crafted packets over the network without authentication, enabling them to execute code on unpatched Windows devices. Microsoft addressed this vulnerability in a security update released on April 14, 2026. This update fixed 165 newly disclosed vulnerabilities, eight of which were rated as critical.

CVE-2026-33824 is a "double free" vulnerability within the Windows IKE Extension component, which handles key exchange for IPsec communications. The vulnerability has a CVSS v3.1 score of 9.8, indicating a critical severity. It allows for remote code execution without administrative privileges or user interaction, and its low attack complexity makes it potentially wormable.

All Windows versions lacking the April 2026 security update are affected. CISA urges all network defenders to prioritize patching this vulnerability to thwart ongoing attacks. For systems unable to apply immediate updates, Microsoft advises blocking external UDP 500 and UDP 4500 traffic if the IKE service is not in use.

Original source: ithome.com