← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 19, 2026 · 16:47via Cyber Security News

CISA Adds Microsoft Internet Key Exchange RCE Vulnerability Exploited in Attacks

Brief

The U. S. Cybersecurity and Infrastructure Security Agency has added a critical Microsoft Internet Key Exchange vulnerability, tracked as CVE-2026-33824, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks.

The flaw affects Microsoft Internet Key Exchange (IKE) Service Extensions and could allow remote code execution on vulnerable systems.

CISA added the vulnerability on August 18, 2026, and set an August 21, 2026, remediation deadline for organizations covered by Binding Operational Directive 26-04.

The short patch window highlights the urgency of the issue and the likelihood that threat actors may actively seek exposed or unpatched Microsoft IKE services.

Microsoft IKE Vulnerability Exploited

CVE-2026-33824 is described as a double-free vulnerability in Microsoft Internet Key Exchange Service Extensions.

Read more on Cyber Security News