CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Summary

Microsoft's Internet Key Exchange (IKE) Service Extensions have a double free vulnerability that could allow for remote code execution. Affected users are instructed to apply vendor-provided mitigations and comply with CISA directives on prioritizing security updates. A federal due date for patching is set for August 21, 2026.

IFF Assessment

FOE

This vulnerability allows for remote code execution, posing a significant risk to systems that are not patched or mitigated.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 21, 2026. Known ransomware use: Unknown.

Defender Context

This critical vulnerability in Microsoft's IKE service presents a significant risk for remote code execution. Defenders must prioritize patching and mitigation efforts, especially given the federal due date. Organizations should also review their asset exposure and ensure compliance with CISA guidance to effectively manage this threat.

Read Full Story →