What is CVE-2026-33824?
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Timeline
- 2026-04-14Published to the U.S. National Vulnerability Database (NVD)
- 2026-08-18Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-08-20First covered in a defend.network daily briefing
- 2026-08-21CISA federal remediation deadline (BOD 22-01)
- 2026-09-25NVD record last updated
CISA Known Exploited Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Affected product
Microsoft Internet Key Exchange (IKE) Service Extensions
NVD also lists CPE entries for: Microsoft Windows 10 1607, Microsoft Windows 10 1809, Microsoft Windows 10 21h2, Microsoft Windows 10 22h2, Microsoft Windows 11 23h2
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities Catalog for affected product details
- Apply vendor patch when available
- Verify patch deployment across affected systems
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
- https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824
- https://nvd.nist.gov/vuln/detail/CVE-2026-33824
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 2 of September 2026 (September 14 – 20)
- Vulnerability Priority Report – Week 1 of September 2026 (September 7 – 13)
- Vulnerability Priority Report – Week 5 of August 2026 (August 31 – September 6)
- Vulnerability Priority Report – Week 4 of August 2026 (August 24 – 30)
- Vulnerability Priority Report – Week 3 of August 2026 (August 17 – 23)
- Microsoft, VMware, Apple vulnerabilities actively exploited; CISA KEV additions demand immediate patching (2026-08-20)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.