• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-33824: pre-auth remote code execution in Microsoft Internet Key Exchange (IKE) Service Extensions

Unauthenticated attackers can trigger a double-free bug in Microsoft Internet Key Exchange (IKE) Service Extensions to achieve remote code execution against affected Windows builds. CVE-2026-33824 impacts multiple Windows 10, Windows 11 and Windows Server 2016 branch builds listed in the vendor advisory and the affected list; fixed build numbers are provided for each branch. An attacker only needs network access to the IKE service; no user interaction or credentials are required to exploit the flaw.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.01619
CWE
CWE-415
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog with a rapid mitigation deadline, so prioritize installing the vendor fixes or applying mitigations immediately.

What is CVE-2026-33824?

Unauthenticated attackers can trigger a double-free bug in Microsoft Internet Key Exchange (IKE) Service Extensions to achieve remote code execution against affected Windows builds. CVE-2026-33824 impacts multiple Windows 10, Windows 11 and Windows Server 2016 branch builds listed in the vendor advisory and the affected list; fixed build numbers are provided for each branch. An attacker only needs network access to the IKE service; no user interaction or credentials are required to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Internet Key Exchange (IKE) Service Extensions are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.906010.0.14393.9060
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.864410.0.17763.8644
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.718410.0.19044.7184
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.718410.0.19045.7184
Windows 11 version 23H2 10.x10.0.22631.0 – before 10.0.22631.693610.0.22631.6936
Windows 11 Version 23H2 10.x10.0.22631.0 – before 10.0.22631.693610.0.22631.6936
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.824610.0.26100.8246
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.824610.0.26200.8246
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.183610.0.28000.1836
Windows Server 2016 10.x10.0.14393.0 – before 10.0.14393.906010.0.14393.9060

Is CVE-2026-33824 being exploited?

CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on 2026-08-18, and U.S. federal agencies were required to remediate by 2026-08-21.

How to fix CVE-2026-33824

  1. Install the Microsoft updates that bring systems to the fixed builds (for example 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184, 10.0.19045.7184, 10.0.22631.6936, 10.0.26100.8246, 10.0.26200.8246, 10.0.28000.1836 as applicable).
  2. If immediate patching is not possible, restrict network exposure to the IKE service using firewall rules and VPN gateway controls.
  3. Follow vendor guidance and CISA’s required actions for prioritizing and documenting remediation per BOD 26-04.
  4. Monitor network and host logs for anomalous IKE traffic and signs of exploitation, and apply incident response procedures if indicators are observed.

Frequently asked questions

Is CVE-2026-33824 being actively exploited?

CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog on 2026-08-18, which required federal agencies to remediate by 2026-08-21.

Which Internet Key Exchange (IKE) Service Extensions versions are affected by CVE-2026-33824?

Multiple Windows 10, Windows 11 and Windows Server 2016 branch builds are listed as affected; the vendor advisory and affected list include specific build ranges for each branch.

Is there a patch for CVE-2026-33824?

Yes. Microsoft published fixes that update affected builds to specific fixed build numbers such as 10.0.14393.9060, 10.0.17763.8644, 10.0.19044.7184, 10.0.19045.7184, 10.0.22631.6936, 10.0.26100.8246, 10.0.26200.8246, and 10.0.28000.1836.

Does CVE-2026-33824 require authentication?

No. The vulnerability in the Internet Key Exchange (IKE) Service Extensions can be exploited without authentication over the network.

References