CISA has added CVE-2026-33824 to its Known Exploited Vulnerabilities catalogue. The entry concerns Microsoft’s Internet Key Exchange (IKE) Service Extensions and covers the Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability, which allows remote code execution through a double free flaw.
The vulnerability is a memory corruption issue caused by improper handling of freed memory in the IKE service extensions. An unauthenticated attacker can send specially crafted packets to trigger the double free, leading to execution of arbitrary code with the privileges of the affected service. The flaw is scored 9.8 on the CVSS v3 scale, rating it critical. Microsoft has released a patch that addresses the issue.
CISA’s inclusion of the CVE in the KEV catalogue confirms that the vulnerability is being actively exploited in the wild. No public reports link this flaw to ransomware campaigns at this time. Federal Civilian Executive Branch agencies must apply the required mitigations by 21 August 2026, the remediation deadline set by CISA.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk and CISA’s Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance or discontinue use of the product if mitigations cannot be applied. Stakeholders must evaluate each asset’s internet exposure and adhere to BOD 26-04 patching guidelines.
While the directive binds FCEB agencies, all organisations are advised to review their exposure to the IKE service extensions and apply the patch or mitigations as soon as practicable.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-33824 and the CISA KEV catalogue.