DIRAS TAKE
Urgent — CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog with a rapid mitigation deadline, so prioritize installing the vendor fixes or applying mitigations immediately.
What is CVE-2026-33824?
Unauthenticated attackers can trigger a double-free bug in Microsoft Internet Key Exchange (IKE) Service Extensions to achieve remote code execution against affected Windows builds. CVE-2026-33824 impacts multiple Windows 10, Windows 11 and Windows Server 2016 branch builds listed in the vendor advisory and the affected list; fixed build numbers are provided for each branch. An attacker only needs network access to the IKE service; no user interaction or credentials are required to exploit the flaw.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Internet Key Exchange (IKE) Service Extensions are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9060 | 10.0.14393.9060 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.8644 | 10.0.17763.8644 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7184 | 10.0.19044.7184 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7184 | 10.0.19045.7184 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.6936 | 10.0.22631.6936 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.6936 | 10.0.22631.6936 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.8246 | 10.0.26100.8246 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.8246 | 10.0.26200.8246 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.1836 | 10.0.28000.1836 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9060 | 10.0.14393.9060 |
Is CVE-2026-33824 being exploited?
CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on 2026-08-18, and U.S. federal agencies were required to remediate by 2026-08-21.
How to fix CVE-2026-33824
- Install the Microsoft updates that bring systems to the fixed builds (for example 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184, 10.0.19045.7184, 10.0.22631.6936, 10.0.26100.8246, 10.0.26200.8246, 10.0.28000.1836 as applicable).
- If immediate patching is not possible, restrict network exposure to the IKE service using firewall rules and VPN gateway controls.
- Follow vendor guidance and CISA’s required actions for prioritizing and documenting remediation per BOD 26-04.
- Monitor network and host logs for anomalous IKE traffic and signs of exploitation, and apply incident response procedures if indicators are observed.
Frequently asked questions
Is CVE-2026-33824 being actively exploited?
CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog on 2026-08-18, which required federal agencies to remediate by 2026-08-21.
Which Internet Key Exchange (IKE) Service Extensions versions are affected by CVE-2026-33824?
Multiple Windows 10, Windows 11 and Windows Server 2016 branch builds are listed as affected; the vendor advisory and affected list include specific build ranges for each branch.
Is there a patch for CVE-2026-33824?
Yes. Microsoft published fixes that update affected builds to specific fixed build numbers such as 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184, 10.0.19045.7184, 10.0.22631.6936, 10.0.26100.8246, 10.0.26200.8246, and 10.0.28000.1836.
Does CVE-2026-33824 require authentication?
No. The vulnerability in the Internet Key Exchange (IKE) Service Extensions can be exploited without authentication over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-33824
- cve.org/CVERecord?id=CVE-2026-33824
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026