www.cisa.gov 8/19/2026, 12:03:51 AM · external

CISA Flags Microsoft IKE Flaw CVE-2026-33824 in KEV Catalog

Developing story vulnerability 2 articles tracked
Microsoft IKE Service Extensions double free vulnerability (CVE-2026-33824) exploited
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as an authoritative resource for vulnerabilities that have been actively exploited in the field, aiding cybersecurity professionals in vulnerability management. Users are encouraged to report any exploited vulnerabilities not listed in the catalog. The catalog includes details on CVE-2026-33824, a Microsoft Internet Key Exchange (IKE) Service Extensions vulnerability that may allow remote code execution.

Organizations should apply vendor-mitigated actions and comply with CISA directives for risk management. The KEV catalog is available in CSV and JSON formats, and users can subscribe for updates.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline