CRITICAL: Windows IKE Flaw CVE-2026-33824 Under Active Exploitation
CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on August 18 after Unit 42 observed hands on keyboard attacks against Windows IKE VPN endpoints. The CVSS 9.8 double free in the Windows IKE Service Extensions gives unauthenticated attackers SYSTEM level code execution over UDP 500 and 4500. Microsoft patched it in April 2026 and federal agencies must remediate by August 21.