Known Exploited Vulnerability
9.8
CRITICAL CVSS 3.1
CVE-2026-33824
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - [Actively Exploited]
Description

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

INFO

Published Date :

April 14, 2026, 6:17 p.m.

Last Modified :

Aug. 19, 2026, 4:16 a.m.

Remotely Exploit :

No
CISA Notification
CISA KEV (Known Exploited Vulnerabilities)

For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.

Description :

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Required Action :

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Known Ransomware Campaign Use:

Unknown

Notes :

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33824 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-33824

Affected Products

The following products are affected by CVE-2026-33824 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Microsoft windows_10
2 Microsoft windows_server_2016
3 Microsoft windows_server_2019
4 Microsoft windows_10_1607
5 Microsoft windows_10_1809
6 Microsoft windows_10_21h2
7 Microsoft windows_10_22h2
8 Microsoft windows_server_2022
9 Microsoft windows_11
10 Microsoft windows_11_23h2
11 Microsoft windows_server_2022_23h2
12 Microsoft windows_server_23h2
13 Microsoft windows_11_24h2
14 Microsoft windows_server_2025
15 Microsoft windows_11_25h2
16 Microsoft windows_11_26h1
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 134c704f-9b21-4f2e-91b3-4a467353bcc0
CVSS 3.1 CRITICAL f38d906d-7342-40ea-92c1-6c4a2c6478c8
CVSS 3.1 CRITICAL [email protected]
Public PoC/Exploit Available at Github

CVE-2026-33824 has a 9 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-33824.

URL Resource
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824 Vendor Advisory
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824 US Government Resource
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-33824 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-33824 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Evidence-first tracker for vulnerabilities claimed to be difficult for AI security systems to discover.

ai-security benchmark github-pages security-research vulnerability-research

JavaScript HTML CSS

Updated: 1 month, 3 weeks ago
0 stars 0 fork 0 watcher
Born at : July 13, 2026, 9:51 a.m. This repo has been linked 4 different CVEs too.

Tracking CVEs discovered by AI systems — Anthropic, OpenAI, Google Big Sleep, Microsoft MDASH, DepthFirst

Updated: 1 month, 4 weeks ago
1 stars 0 fork 0 watcher
Born at : May 26, 2026, 1:31 a.m. This repo has been linked 208 different CVEs too.

IKEv2, ikeext.dll, CVE-2026-33824, double free, heap grooming, ROP, SKF fragmentation, Windows exploit, anti-debug, obfuscation, API hooking, shellcode, reverse shell

C++ Python

Updated: 2 months, 1 week ago
4 stars 0 fork 0 watcher
Born at : May 18, 2026, 1:44 p.m. This repo has been linked 1 different CVEs too.

Cybersecurity Vulnerability Report: May 2026

Updated: 4 months ago
0 stars 0 fork 0 watcher
Born at : May 1, 2026, 9:36 a.m. This repo has been linked 15 different CVEs too.

None

Updated: 4 months ago
0 stars 0 fork 0 watcher
Born at : April 28, 2026, 7:14 p.m. This repo has been linked 2 different CVEs too.

None

Updated: 4 months, 1 week ago
0 stars 0 fork 0 watcher
Born at : April 23, 2026, 7:24 p.m. This repo has been linked 2 different CVEs too.

None

Updated: 4 months, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : April 21, 2026, 3:29 p.m. This repo has been linked 1 different CVEs too.

Windows IKEv2 Double-Free RCE

Updated: 4 months, 2 weeks ago
0 stars 0 fork 0 watcher
Born at : April 16, 2026, 2:01 p.m. This repo has been linked 1 different CVEs too.

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

security cve exploit poc vulnerability

Updated: 1 month, 2 weeks ago
7922 stars 1275 fork 1275 watcher
Born at : Dec. 8, 2019, 1:03 p.m. This repo has been linked 646 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-33824 vulnerability anywhere in the article.

  • europa.eu
Cyber Brief 26-09 - August 2026

Cyber Brief (August 2026)September 3, 2026 - Version 1TLP:CLEARExecutive summaryWe analysed 385 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, two alleged memb ... Read more

Published Date: Sep 03, 2026 (1 day, 2 hours ago)
  • SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 34

The Good | U.S. Charges Iranian Cyberattackers Over Mass Intellectual Property Theft The U.S. Justice Department has indicted 17 Iranian nationals associated with the Mabna Institute, a state-sponsore ... Read more

Published Date: Aug 21, 2026 (2 weeks ago)
  • SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 34

The Good | U.S. Charges Iranian Cyberattackers Over Mass Intellectual Property Theft The U.S. Justice Department has indicted 17 Iranian nationals associated with the Mabna Institute, a state-sponsore ... Read more

Published Date: Aug 21, 2026 (2 weeks ago)
  • TheCyberThrone
CISA Adds Five Actively Exploited Vulnerabilities to KEV in Just Two Days

A Five-Vulnerability Warning: From AI Infrastructure to Virtualization and Enterprise CollaborationThe U.S. Cybersecurity and Infrastructure  Security Agency (CISA) has added five vulnerabilities to i ... Read more

Published Date: Aug 20, 2026 (2 weeks, 1 day ago)
  • security.nl
Kritiek beveiligingslek in Windows IKE-extensie misbruikt bij aanvallen

Een kritieke kwetsbaarheid in de Windows Internet Key Exchange (IKE)-extensie, die remote code execution op Windowssystemen mogelijk (RCE) maakt, wordt misbruikt bij aanvallen. Dat meldt het Amerikaan ... Read more

Published Date: Aug 19, 2026 (2 weeks, 2 days ago)
  • The Hacker News
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited i ... Read more

Published Date: Aug 19, 2026 (2 weeks, 2 days ago)
  • The Hacker News
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in t ... Read more

Published Date: Aug 05, 2026 (4 weeks, 2 days ago)
  • The Hacker News
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

A lot of security still comes down to trusting the wrong screen.This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind ... Read more

Published Date: Jul 30, 2026 (1 month ago)
  • TheCyberThrone
Microsoft MDASH: When the Machine Becomes the Red Team

AI-native vulnerability discovery has crossed from research curiosity into production-grade defense — and the implications for how enterprises think about security engineering are irreversible.The Ann ... Read more

Published Date: May 14, 2026 (3 months, 3 weeks ago)
  • The Hacker News
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's being tested by some c ... Read more

Published Date: May 13, 2026 (3 months, 3 weeks ago)
  • Zero Day Initiative
CVE-2026-33824: Remote Code Execution in Windows IKEv2

__int64 IkeReinjectReassembledPacket{ void *pFragList, __int64 pMMSA, __int64 *pFragContext, __int64 pMMSACtx} { IKE_RECV_CONTEXT recvCtx; memset(&recvCtx, 0, 0xF0); dwReassembledSize = 0; status = Wf ... Read more

Published Date: Apr 23, 2026 (4 months, 1 week ago)
  • Daily CyberSecurity
Wormable Bugs: Microsoft April 2026 Patch Tuesday Fixes Two “Zero-Interaction” RCE Flaws

The security landscape for Windows administrators just got significantly more urgent. As part of the April 2026 Patch Tuesday rollout, Microsoft has addressed a pair of high-impact vulnerabilities tha ... Read more

Published Date: Apr 17, 2026 (4 months, 2 weeks ago)
  • CrowdStrike.com
April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs

Microsoft has addressed 164 vulnerabilities in its April 2026 security update release, double the number of vulnerabilities in March 2026. These include one exploited zero-day vulnerability, one previ ... Read more

Published Date: Apr 15, 2026 (4 months, 2 weeks ago)
  • The Cyber Express
Microsoft Fixes 167 Vulnerabilities in Latest Patch Tuesday Update

Microsoft’s Patch Tuesday April 2026 release has introduced one of the most extensive security update rollouts of the year, addressing a total of 167 vulnerabilities across Windows operating systems a ... Read more

Published Date: Apr 15, 2026 (4 months, 2 weeks ago)
  • TheCyberThrone
Microsoft Patch Tuesday — April 2026

TheCyberThrone | Vulnerability Advisory | April 15, 2026Volume & Scale — A Near-Record ReleaseMicrosoft patched 163 CVEs in the April 2026 Patch Tuesday release — the second largest Patch Tuesday on r ... Read more

Published Date: Apr 15, 2026 (4 months, 2 weeks ago)

The following table lists the changes that have been made to the CVE-2026-33824 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Aug. 19, 2026

    Action Type Old Value New Value
    Changed SSVC {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-08-18T17:44:04.148157Z'} {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-13T00:00:00+00:00'}
  • Modified Analysis by [email protected]

    Aug. 18, 2026

    Action Type Old Value New Value
    Added Reference Type CISA-ADP: https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ Types: Third Party Advisory
    Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824 Types: US Government Resource
  • CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725

    Aug. 18, 2026

    Action Type Old Value New Value
    Added Date Added 2026-08-18
    Added Due Date 2026-08-18
    Added Required Action 2026-08-18
    Added Vulnerability Name 2026-08-18
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Aug. 18, 2026

    Action Type Old Value New Value
    Added Reference https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
    Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824
    Changed SSVC {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-15T03:57:42.655846Z'} {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-08-18T17:44:04.148157Z'}
  • CVE Translated by [email protected]

    Jul. 24, 2026

    Action Type Old Value New Value
    Added Translation Title: Microsoft, Description: Doble liberación en la extensión IKE de Windows permite a un atacante no autorizado ejecutar código a través de una red.
  • CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0

    Jun. 17, 2026

    Action Type Old Value New Value
    Added SSVC {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-15T03:57:42.655846Z'}
  • CVE Modified by [email protected]

    Jun. 17, 2026

    Action Type Old Value New Value
    Added Affected [{'vendor': 'Microsoft', 'product': 'Windows 10 Version 1607', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.9060', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 1809', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.8644', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 21H2', 'versions': [{'status': 'affected', 'version': '10.0.19044.0', 'lessThan': '10.0.19044.7184', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 22H2', 'versions': [{'status': 'affected', 'version': '10.0.19045.0', 'lessThan': '10.0.19045.7184', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 version 22H3', 'versions': [{'status': 'affected', 'version': '10.0.22631.0', 'lessThan': '10.0.22631.6936', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 23H2', 'versions': [{'status': 'affected', 'version': '10.0.22631.0', 'lessThan': '10.0.22631.6936', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 24H2', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.8246', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 25H2', 'versions': [{'status': 'affected', 'version': '10.0.26200.0', 'lessThan': '10.0.26200.8246', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 version 26H1', 'versions': [{'status': 'affected', 'version': '10.0.28000.0', 'lessThan': '10.0.28000.1836', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2016', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.9060', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2016 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.9060', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2019', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.8644', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2019 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.8644', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2022', 'versions': [{'status': 'affected', 'version': '10.0.20348.0', 'lessThan': '10.0.20348.5020', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.25398.0', 'lessThan': '10.0.25398.2274', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2025', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.32690', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2025 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.32690', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}]
  • Initial Analysis by [email protected]

    Apr. 17, 2026

    Action Type Old Value New Value
    Added CPE Configuration OR *cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.14393.9060 *cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.14393.9060 *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.17763.8644 *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.17763.8644 *cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.19044.7184 *cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.19044.7184 *cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.19044.7184 *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.19045.7184 *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.19045.7184 *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.19045.7184 *cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.22631.6936 *cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.22631.6936 *cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.26100.8246 *cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.26100.8246 *cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.26200.8246 *cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.26200.8246 *cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.28000.1836 *cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.28000.1836 *cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.14393.9060 *cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.17763.8644 *cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.20348.5020 *cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.25398.2274 *cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.26100.32690
    Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824 Types: Vendor Advisory
  • New CVE Received by [email protected]

    Apr. 14, 2026

    Action Type Old Value New Value
    Added Description Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-415
    Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.