CVE-2026-33824
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - [Actively Exploited]
Description
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
INFO
Published Date :
April 14, 2026, 6:17 p.m.
Last Modified :
Aug. 19, 2026, 4:16 a.m.
Remotely Exploit :
No
Source :
[email protected]
CISA KEV (Known Exploited Vulnerabilities)
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Unknown
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-33824 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-33824
Affected Products
The following products are affected by CVE-2026-33824
vulnerability.
Even if cvefeed.io is aware of the exact versions of the
products
that
are
affected, the information is not represented in the table below.
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | CRITICAL | f38d906d-7342-40ea-92c1-6c4a2c6478c8 | ||||
| CVSS 3.1 | CRITICAL | [email protected] |
Public PoC/Exploit Available at Github
CVE-2026-33824 has a 9 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-33824.
| URL | Resource |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824 | Vendor Advisory |
| https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824 | US Government Resource |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-33824 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-33824
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Evidence-first tracker for vulnerabilities claimed to be difficult for AI security systems to discover.
ai-security benchmark github-pages security-research vulnerability-research
JavaScript HTML CSS
Tracking CVEs discovered by AI systems — Anthropic, OpenAI, Google Big Sleep, Microsoft MDASH, DepthFirst
IKEv2, ikeext.dll, CVE-2026-33824, double free, heap grooming, ROP, SKF fragmentation, Windows exploit, anti-debug, obfuscation, API hooking, shellcode, reverse shell
C++ Python
Cybersecurity Vulnerability Report: May 2026
None
None
None
Windows IKEv2 Double-Free RCE
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
security cve exploit poc vulnerability
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-33824 vulnerability anywhere in the article.
-
europa.eu
Cyber Brief 26-09 - August 2026
Cyber Brief (August 2026)September 3, 2026 - Version 1TLP:CLEARExecutive summaryWe analysed 385 open source reports for this Cyber Brief1.Relating to cyber policy and law enforcement, two alleged memb ... Read more
-
SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 34
The Good | U.S. Charges Iranian Cyberattackers Over Mass Intellectual Property Theft The U.S. Justice Department has indicted 17 Iranian nationals associated with the Mabna Institute, a state-sponsore ... Read more
-
SentinelOne
The Good, the Bad and the Ugly in Cybersecurity – Week 34
The Good | U.S. Charges Iranian Cyberattackers Over Mass Intellectual Property Theft The U.S. Justice Department has indicted 17 Iranian nationals associated with the Mabna Institute, a state-sponsore ... Read more
-
TheCyberThrone
CISA Adds Five Actively Exploited Vulnerabilities to KEV in Just Two Days
A Five-Vulnerability Warning: From AI Infrastructure to Virtualization and Enterprise CollaborationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to i ... Read more
-
security.nl
Kritiek beveiligingslek in Windows IKE-extensie misbruikt bij aanvallen
Een kritieke kwetsbaarheid in de Windows Internet Key Exchange (IKE)-extensie, die remote code execution op Windowssystemen mogelijk (RCE) maakt, wordt misbruikt bij aanvallen. Dat meldt het Amerikaan ... Read more
-
The Hacker News
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited i ... Read more
-
The Hacker News
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in t ... Read more
-
The Hacker News
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A lot of security still comes down to trusting the wrong screen.This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind ... Read more
-
TheCyberThrone
Microsoft MDASH: When the Machine Becomes the Red Team
AI-native vulnerability discovery has crossed from research curiosity into production-grade defense — and the implications for how enterprises think about security engineering are irreversible.The Ann ... Read more
-
The Hacker News
Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's being tested by some c ... Read more
-
Zero Day Initiative
CVE-2026-33824: Remote Code Execution in Windows IKEv2
__int64 IkeReinjectReassembledPacket{ void *pFragList, __int64 pMMSA, __int64 *pFragContext, __int64 pMMSACtx} { IKE_RECV_CONTEXT recvCtx; memset(&recvCtx, 0, 0xF0); dwReassembledSize = 0; status = Wf ... Read more
-
Daily CyberSecurity
Wormable Bugs: Microsoft April 2026 Patch Tuesday Fixes Two “Zero-Interaction” RCE Flaws
The security landscape for Windows administrators just got significantly more urgent. As part of the April 2026 Patch Tuesday rollout, Microsoft has addressed a pair of high-impact vulnerabilities tha ... Read more
-
CrowdStrike.com
April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs
Microsoft has addressed 164 vulnerabilities in its April 2026 security update release, double the number of vulnerabilities in March 2026. These include one exploited zero-day vulnerability, one previ ... Read more
-
The Cyber Express
Microsoft Fixes 167 Vulnerabilities in Latest Patch Tuesday Update
Microsoft’s Patch Tuesday April 2026 release has introduced one of the most extensive security update rollouts of the year, addressing a total of 167 vulnerabilities across Windows operating systems a ... Read more
-
TheCyberThrone
Microsoft Patch Tuesday — April 2026
TheCyberThrone | Vulnerability Advisory | April 15, 2026Volume & Scale — A Near-Record ReleaseMicrosoft patched 163 CVEs in the April 2026 Patch Tuesday release — the second largest Patch Tuesday on r ... Read more
The following table lists the changes that have been made to the
CVE-2026-33824 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Aug. 19, 2026
Action Type Old Value New Value Changed SSVC {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-08-18T17:44:04.148157Z'} {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-13T00:00:00+00:00'} -
Modified Analysis by [email protected]
Aug. 18, 2026
Action Type Old Value New Value Added Reference Type CISA-ADP: https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ Types: Third Party Advisory Added Reference Type CISA-ADP: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824 Types: US Government Resource -
CVE CISA KEV Update by 9119a7d8-5eab-497f-8521-727c672e3725
Aug. 18, 2026
Action Type Old Value New Value Added Date Added 2026-08-18 Added Due Date 2026-08-18 Added Required Action 2026-08-18 Added Vulnerability Name 2026-08-18 -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Aug. 18, 2026
Action Type Old Value New Value Added Reference https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ Added Reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824 Changed SSVC {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-15T03:57:42.655846Z'} {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'active'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-08-18T17:44:04.148157Z'} -
CVE Translated by [email protected]
Jul. 24, 2026
Action Type Old Value New Value Added Translation Title: Microsoft, Description: Doble liberación en la extensión IKE de Windows permite a un atacante no autorizado ejecutar código a través de una red. -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-33824', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'yes'}, {'technicalImpact': 'total'}], 'version': '2.0.3', 'timestamp': '2026-04-15T03:57:42.655846Z'} -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'Microsoft', 'product': 'Windows 10 Version 1607', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.9060', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 1809', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.8644', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 21H2', 'versions': [{'status': 'affected', 'version': '10.0.19044.0', 'lessThan': '10.0.19044.7184', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 10 Version 22H2', 'versions': [{'status': 'affected', 'version': '10.0.19045.0', 'lessThan': '10.0.19045.7184', 'versionType': 'custom'}], 'platforms': ['32-bit Systems', 'ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 version 22H3', 'versions': [{'status': 'affected', 'version': '10.0.22631.0', 'lessThan': '10.0.22631.6936', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 23H2', 'versions': [{'status': 'affected', 'version': '10.0.22631.0', 'lessThan': '10.0.22631.6936', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 24H2', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.8246', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 Version 25H2', 'versions': [{'status': 'affected', 'version': '10.0.26200.0', 'lessThan': '10.0.26200.8246', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows 11 version 26H1', 'versions': [{'status': 'affected', 'version': '10.0.28000.0', 'lessThan': '10.0.28000.1836', 'versionType': 'custom'}], 'platforms': ['ARM64-based Systems', 'x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2016', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.9060', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2016 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.14393.0', 'lessThan': '10.0.14393.9060', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2019', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.8644', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2019 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.17763.0', 'lessThan': '10.0.17763.8644', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2022', 'versions': [{'status': 'affected', 'version': '10.0.20348.0', 'lessThan': '10.0.20348.5020', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2022, 23H2 Edition (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.25398.0', 'lessThan': '10.0.25398.2274', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2025', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.32690', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}, {'vendor': 'Microsoft', 'product': 'Windows Server 2025 (Server Core installation)', 'versions': [{'status': 'affected', 'version': '10.0.26100.0', 'lessThan': '10.0.26100.32690', 'versionType': 'custom'}], 'platforms': ['x64-based Systems']}] -
Initial Analysis by [email protected]
Apr. 17, 2026
Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.14393.9060 *cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.14393.9060 *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.17763.8644 *cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.17763.8644 *cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.19044.7184 *cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.19044.7184 *cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.19044.7184 *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.19045.7184 *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.19045.7184 *cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:* versions up to (excluding) 10.0.19045.7184 *cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.22631.6936 *cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.22631.6936 *cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.26100.8246 *cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.26100.8246 *cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.26200.8246 *cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.26200.8246 *cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:* versions up to (excluding) 10.0.28000.1836 *cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:* versions up to (excluding) 10.0.28000.1836 *cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.14393.9060 *cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.17763.8644 *cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.20348.5020 *cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.25398.2274 *cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* versions up to (excluding) 10.0.26100.32690 Added Reference Type Microsoft Corporation: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824 Types: Vendor Advisory -
New CVE Received by [email protected]
Apr. 14, 2026
Action Type Old Value New Value Added Description Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Added CWE CWE-415 Added Reference https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824