AIO APEX

CISA confirms active attacks on critical Windows IKE flaw, gives agencies 3 days to patch

BleepingComputer
Share:
CISA confirms active attacks on critical Windows IKE flaw, gives agencies 3 days to patch

A critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions is being actively exploited in the wild, according to the Cybersecurity and Infrastructure Security Agency. CISA added the vulnerability, tracked as CVE-2026-33824, to its Known Exploited Vulnerabilities catalog on August 18, giving U.S. federal civilian agencies just three days — until August 21 — to apply mitigations under Binding Operational Directive 26-04.

The flaw affects every currently supported release of Windows 10, Windows 11, and Windows Server, making it one of the broadest-reaching Windows vulnerabilities disclosed this year.

How the attack works

CVE-2026-33824 is a double-free memory corruption bug in the IKE Service Extensions (MS-IKEE), the component Windows uses to negotiate IPsec VPN connections. An unauthenticated attacker can send specially crafted packets to UDP ports 500 or 4500 — the standard ports IKE uses for VPN negotiation — to trigger the double-free condition and execute arbitrary code with the privileges of the affected service. No credentials or user interaction are required, and the vulnerability is remotely exploitable over the network.

Who's behind the attacks

According to security researchers, the exploitation has been narrow and targeted so far rather than mass scanning. Palo Alto Networks' Unit 42 observed a Chinese-speaking threat actor manually sending reverse-shell callbacks to three IKE VPN endpoints using this exploit — a pattern consistent with deliberate, hands-on-keyboard intrusion rather than automated opportunistic attacks. Notably, Microsoft had not updated its own advisory to reflect active exploitation at the time CISA added the flaw to its catalog, an unusual gap between vendor and government threat intelligence.

What administrators need to do now

CISA's guidance is direct: apply Microsoft's security update immediately. For systems where IKE-based VPN connectivity isn't in use, administrators should block inbound UDP ports 500 and 4500 entirely. Where IKE is required — for site-to-site or remote-access VPNs — firewall rules should be tightened to only accept traffic from known, trusted peer addresses rather than leaving the ports open to the internet.

Because any Windows system exposing IKE to untrusted networks is a viable target, the exposure isn't limited to federal agencies — the same three-day urgency implied by CISA's directive applies to any organization running VPN gateways on affected Windows versions.

Part of a busier-than-usual patch cycle

This disclosure follows Microsoft's August 2026 Patch Tuesday, which fixed roughly 400 flaws including several zero-days — and comes in the same week security researchers separately disclosed a Defender privilege-escalation bypass known as ShieldBreak. The clustering of high-severity, actively exploited Windows bugs this month underscores why CISA's Known Exploited Vulnerabilities catalog exists: patch prioritization matters more than patch volume when multiple critical issues land in the same window.

As reported by BleepingComputer, CVE-2026-33824 was added to CISA's catalog on August 18, 2026, with federal remediation required by August 21.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share:
CISA confirms active attacks on critical Windows IKE flaw, gives agencies 3 days to patch | AIO APEX