Skip to content
Critical RCE Vulnerability in Windows IKE Actively Exploited

Critical RCE Vulnerability in Windows IKE Actively Exploited

First seen 19 Aug 2026, 10:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 20, 2026 at 10:23 UTC
  • •CVE-2026-33824 allows unauthenticated remote code execution on Windows systems.
  • •Exploitation can occur via crafted IKEv2 packets sent through UDP ports 500 or 4500.
  • •CISA has classified this vulnerability as actively exploited, urging immediate remediation.

A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported versions of Windows 10, Windows 11, and Windows Server. Attackers can exploit the vulnerability remotely without authentication by sending specially crafted IKEv2 packets through UDP ports 500 or 4500. The exploitation allows unauthorized code execution with SYSTEM privileges, posing significant risks to affected systems. CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog, urging immediate action from federal agencies and all network defenders. Microsoft had previously patched the vulnerability on April 14, 2026, but the assessment of its exploitability has changed. Security teams are advised to block inbound traffic on the affected ports if immediate patching is not possible. The situation is critical, with ongoing attacks reported.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 44d ago How this analysis works

Timeline

2026-04-14
CVE-2026-33824 patched
Microsoft released a patch for a critical RCE vulnerability in Windows IKE.
Op-C
2026-05-22
CVE-2026-45659 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-50522 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-55040 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-30
CVE-2026-59310 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-06
CVE-2026-65400 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CISA adds CVE-2026-33824 to KEV Catalog
CISA confirmed active exploitation of the vulnerability, urging immediate action from federal agencies.
Bleepingcomputer
2026-08-20
Ongoing attacks reported
Security teams are advised to take action as attacks exploiting CVE-2026-33824 are confirmed.
Op-C

More articles in this cluster (4)

Following this threat?

Track CVE-2026-33824 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed