"Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network," Microsoft said in its April 2026 advisory — and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) now says attackers are doing exactly that.
What CVE-2026-33824 is and which systems it touches
Tracked as CVE-2026-33824, the flaw exists in the Windows Internet Key Exchange (IKE) Service Extensions component — also identified as MS-IKEE. Microsoft describes MS-IKEE as a set of additional capabilities for IKE, including authentication via cryptographically generated addresses (CGAs), denial-of-service protection, and easier interoperability with non-Internet Protocol Security (IPsec)–capable peers. The vulnerability affects all supported Windows 10, Windows 11, and Windows Server releases.
How the vulnerability is exploited: vectors and prerequisites
Microsoft says the bug is a double-free condition that “allows an unauthorized attacker to execute code over a network.” An attacker who does not have privileges can gain remote code execution by sending specially crafted packets to an unpatched Windows machine with Internet Key Exchange version 2 enabled. The exploit path is network-facing: packets arrive over UDP ports 500 or 4500.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildCISA’s escalation: active exploitation and a three-day order for federal agencies
Although Microsoft has not updated its advisory to label the flaw as exploited in the wild, CISA has added CVE-2026-33824 to its catalog of actively exploited vulnerabilities. Under Binding Operational Directive 26-04, CISA ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure affected devices within three days. CISA warned that “this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” and urged all network defenders to prioritize patching to interrupt ongoing attacks.
Mitigation guidance Microsoft issued and what to do if you can’t patch
Microsoft released a security update during the April 2026 Patch Tuesday cycle to address CVE-2026-33824. For teams that cannot immediately apply the update, Microsoft advised two temporary mitigations: block inbound traffic on UDP ports 500 and 4500 for systems that do not use IKE; or, where IKE is required, configure firewall rules to allow inbound traffic only from known peer addresses.
What this means for FCEB agencies, security teams, and affected enterprises
- FCEB agencies: CISA’s three-day remediation order under BOD 26-04 requires fast, centrally tracked action on all affected systems. The directive is mandatory for federal civilian agencies and sets an aggressive timetable to stop active exploitation.
- Security teams and technologists: Teams must weigh immediate patch deployment against network segmentation and firewall workarounds. Microsoft’s packet/port mitigations give an interim path, but the vendor update is the definitive fix for the RCE vector described.
- Affected enterprises: Organizations running supported Windows 10, Windows 11, or Windows Server editions that have IKEv2 enabled must identify exposed endpoints listening on UDP 500/4500 and prioritize either patching or the temporary firewall measures Microsoft recommended.
CISA’s public catalog places this incident alongside a growing list: since November 2021 the agency has tagged 385 actively exploited Microsoft-related vulnerabilities, 112 of which ransomware gangs have also exploited. In recent weeks CISA confirmed that a previously flagged high-severity Windows Task Host vulnerability is being abused in ransomware attacks, and warned that ransomware operations are using a Microsoft SharePoint RCE vulnerability after in-the-wild exploitation was confirmed in early July.
There is one more detail that underscores the stakes: the Blue Report 2026 — cited in the source material — notes that “overall prevention scores can hide what happens after initial access,” adding that “once attackers are using valid credentials, prevention drops sharply.” That observation underlines why CISA moved CVE-2026-33824 into its actively exploited catalog and why it issued a short remediation window for federal systems.
Microsoft and CISA spokespeople had not responded to BleepingComputer’s request for further comment at the time the advisory was reported. For defenders, the path forward is concrete: install the April 2026 security update, or apply the vendor’s prescribed port and firewall mitigations without delay.




