ZeroDayAlert

CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Microsoft Internet Key Exchange (IKE) Service Extensions Added to KEV 2026-08-18 Federal due 2026-08-21 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability allowing remote code execution. The record does not specify which versions of Windows or which deployment configurations are vulnerable, nor whether on-premises and cloud deployments are equally affected. You are affected if you operate IKE Service Extensions in your environment.

How to check whether this touches you

  • Inventory check: Confirm whether IKE Service Extensions is installed and enabled on any Windows systems you manage. Check Group Policy, system configuration, and VPN or IPsec gateway deployments.
  • Reachability: If IKE Service Extensions is exposed on network interfaces reachable from untrusted networks (including the internet), the attack surface is highest. Determine whether your IKE endpoints are restricted to internal or partner networks only.
  • Version fingerprinting: Obtain the version numbers of IKE Service Extensions from affected systems. Consult Microsoft's security advisory to map your versions against the vulnerable range; note that some backported patches may complicate version-based assessment.
  • Usage context: Identify whether IKE Service Extensions is actively used for VPN, remote access, or site-to-site connectivity, or whether it is installed but dormant.

What to do

  1. Obtain Microsoft's official guidance immediately. Microsoft will publish a security advisory and patch availability. Retrieve the specific remediation steps from Microsoft's security update page for CVE-2026-33824.
  2. If you cannot patch within the federal deadline (21 August 2026), apply Microsoft's interim mitigations without delay. These may include disabling the service, restricting network access via firewall rules, or applying workarounds; follow Microsoft's instructions precisely.
  3. Reduce reachability. If IKE Service Extensions is internet-facing, restrict access to authorised peer IP addresses and consider moving VPN endpoints behind a bastion or load balancer if architecture permits.
  4. Enable logging. Configure audit logging on IKE Service Extensions and upstream firewalls to capture connection attempts, especially any that fail or appear anomalous.
  5. Plan patching. Align your patch deployment with CISA's BOD 26-04 guidance, prioritising internet-exposed systems and critical infrastructure. Test patches in a staging environment before production rollout.
  6. Escalate if mitigations are unavailable. If Microsoft does not provide a patch or workaround by the remediation deadline, engage your Chief Information Security Officer and evaluate whether discontinuing use of IKE Service Extensions is feasible for your operations.

If you find you were exposed

Exploitation of a double free vulnerability typically requires network proximity and does not leave obvious application-level traces. Review firewall and VPN gateway logs from before the record publication date (18 August 2026) for anomalous IKE traffic, failed authentications, or service crashes that might indicate exploitation attempts. Retain at least 90 days of logs if you have not already done so; older logs may have been rotated out, limiting retrospective visibility.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-33824 is being exploited. It cannot tell you whether Internet Key Exchange (IKE) Service Extensions is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →