CyberSecurityNews

CISA Adds Microsoft Internet Key Exchange RCE Vulnerability Exploited in Attacks


The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Microsoft Internet Key Exchange vulnerability, tracked as CVE-2026-33824, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks.

The flaw affects Microsoft Internet Key Exchange (IKE) Service Extensions and could allow remote code execution on vulnerable systems.

CISA added the vulnerability on August 18, 2026, and set an August 21, 2026, remediation deadline for organizations covered by Binding Operational Directive 26-04.

The short patch window highlights the urgency of the issue and the likelihood that threat actors may actively seek exposed or unpatched Microsoft IKE services.

Microsoft IKE Vulnerability Exploited

CVE-2026-33824 is described as a double-free vulnerability in Microsoft Internet Key Exchange Service Extensions. A double-free condition occurs when software releases the same memory area more than once.

Attackers can potentially manipulate the resulting memory corruption to crash a service, leak information, or execute attacker-controlled code.

The vulnerability is associated with CWE-415, a weakness category covering double-free flaws. If exploitation can be performed remotely and without authentication, the issue may be especially dangerous for systems that expose IKE-related services to the internet.

IKE is a core protocol component commonly used in Internet Protocol Security (IPsec) deployments. It negotiates security associations and cryptographic keys for VPN connections.

A successful compromise of an IKE-enabled endpoint could give attackers a foothold on a perimeter device or Windows system supporting VPN-related connectivity.

CISA currently lists ransomware use for CVE-2026-33824 as unknown, with Microsoft yet to publicly link the flaw to any specific ransomware operation..

However, remote code execution bugs in externally reachable network services are often valuable to initial-access brokers, espionage groups, and ransomware affiliates because they enable entry without relying on phishing or stolen credentials.

CISA advised organizations to apply vendor-provided mitigations in accordance with Microsoft’s instructions and to follow BOD 26-04, which prioritizes security updates according to risk.

Agencies and affected organizations should identify assets running Microsoft IKE Service Extensions, determine whether they are exposed to untrusted networks, and install the relevant security update as quickly as possible.

Security teams should not limit response efforts to patch deployment. They should also review perimeter logs, VPN and IPsec telemetry, Windows event logs, endpoint alerts, and network traffic for signs of suspicious activity involving IKE services.

Unexpected service crashes, repeated malformed connection attempts, unusual processes spawned by system services, and outbound traffic from VPN infrastructure warrant investigation.

Organizations that cannot immediately patch should reduce exposure where possible. This may include restricting IKE traffic to trusted networks, limiting UDP ports 500 and 4500 at perimeter firewalls where operationally feasible, and isolating affected hosts from the public internet.

Any temporary workaround should be treated as a short-term control rather than a replacement for applying Microsoft’s fix. CISA also instructed stakeholders to follow applicable forensics triage requirements and evaluate each asset’s internet exposure.

Organizations unable to deploy effective mitigations should consider discontinuing use of the vulnerable product or service until a secure configuration is available.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



Source link