CISA Warns CVE-2026-33824 Windows IKE Remote Code Execution Flaw Is Being Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are actively exploiting a critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) service extension component.
Known as MS-IKEE, the Windows IKE Extension adds several capabilities to the Internet Key Exchange protocol, including cryptographically generated address (CGA) authentication, denial-of-service protection, and improved interoperability with peers that do not support Internet Protocol Security (IPsec).
Tracked as CVE-2026-33824, the Windows IKE vulnerability affects all supported Windows 10, Windows 11, and Windows Server versions. An unauthenticated, unprivileged attacker can exploit the flaw by sending specially crafted packets to an unpatched Windows system over UDP ports 500 or 4500.
Microsoft describes CVE-2026-33824 as a “double free” vulnerability in the Windows IKE Extension that could allow an unprivileged attacker to execute code remotely over a network. The company disclosed the flaw in an advisory released during the April 2026 Patch Tuesday security updates.
“An unauthenticated attacker could send a specially crafted packet to a Windows machine that has Internet Key Exchange (IKE) version 2 enabled, resulting in remote code execution,” Microsoft says.
Organizations that cannot immediately install the CVE-2026-33824 security update should block incoming traffic on UDP ports 500 and 4500 for systems that do not use IKE. For systems that require IKE, Microsoft recommends configuring firewall rules to allow traffic only from trusted, known peer addresses.
CVE-2026-33824 added to CISA’s Known Exploited Vulnerabilities Catalog
Microsoft has not yet updated its security advisory to confirm exploitation. However, CISA has added CVE-2026-33824 to its Known Exploited Vulnerabilities Catalog.
CISA has directed U.S. federal civilian executive branch (FCEB) agencies to secure affected systems within three days, as required by Binding Operational Directive 26-04.
The agency warned that vulnerabilities of this type are frequently used by malicious cyber actors and pose significant risks to federal networks. Although BOD 26-04 applies only to government agencies, CISA urged all organizations and network defenders to prioritize patching CVE-2026-33824 because the Windows IKE flaw is being exploited in ongoing attacks.
CISA recently added other actively exploited Microsoft vulnerabilities to its catalog. A high-severity flaw in Windows Task Host is also being exploited, including in ransomware attacks. Last week, the agency warned that ransomware groups were beginning to exploit a remote code execution vulnerability in Microsoft SharePoint after attacks targeting the flaw were observed in the wild in early July.
Since November 2021, CISA has listed 385 actively exploited vulnerabilities affecting Microsoft products. Of those vulnerabilities, 112 have also been exploited by ransomware groups.
CISA and Microsoft have not yet responded to requests for additional information about the attacks targeting the CVE-2026-33824 Windows IKE vulnerability.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




