Critical RCE Vulnerability in Windows IKE Actively Exploited

Critical RCE Vulnerability in Windows IKE Actively Exploited

First seen 19 Aug 2026, 10:33 UTC Heise.DeBleepingcomputer 76% similarity 75.9

Article Content

Browse articles
ThreatCluster

CISA has issued a warning regarding the active exploitation of a critical remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions, tracked as CVE-2026-33824. This flaw affects all supported versions of Windows 10, Windows 11, and Windows Server, allowing unauthenticated attackers to execute code remotely by sending specially crafted packets through UDP ports 500 or 4500. Microsoft addressed this vulnerability in April 2026, but it has only recently been added to CISA's catalog of actively exploited vulnerabilities. CISA has mandated that U.S. Federal Civilian Executive Branch agencies secure their devices within three days. Additionally, other vulnerabilities in Microsoft SharePoint and VMware vCenter are also under active attack, highlighting a broader trend of exploitation across multiple platforms. Security teams are urged to prioritize patching and monitoring for signs of intrusion. The situation is critical as attackers leverage these vulnerabilities to gain unauthorized access.

Key Points: • CVE-2026-33824 is a critical RCE vulnerability in Windows IKE, affecting multiple Windows versions. • CISA has mandated federal agencies to secure devices within three days due to active exploitation. • Other vulnerabilities in Microsoft SharePoint and VMware vCenter are also being actively exploited.

ThreatCluster AI How this analysis works

Timeline

2026-04-14
CVE-2026-33824 published
Microsoft disclosed a critical RCE vulnerability in Windows IKE Service Extensions.
BleepingComputer
2026-05-22
CVE-2026-45659 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-50522 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
CVE-2026-59310 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-33824 added to CISA KEV
CISA confirmed active exploitation of the Windows IKE vulnerability, urging immediate action.
BleepingComputer
2026-08-18
CVE-2026-55040 added to CISA KEV
CISA warned of active exploitation of a critical SharePoint vulnerability, CVE-2026-55040.
Heise.De
2026-08-18
CVE-2026-65400 added to CISA KEV
CISA confirmed active exploitation of a critical macOS vulnerability, CVE-2026-65400.
Heise.De
2026-08-19
CISA issues urgent warning
CISA warns all network defenders to prioritize patching CVE-2026-33824 and related vulnerabilities.
BleepingComputer

Community

Browse all →