LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 18, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 21, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog on Aug 18, 2026, with a federal patch deadline of Aug 21, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

CVE-2026-33824 is a double-free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions. In plain terms, flawed memory handling in this IKE-related component can leave the service in an unsafe state that an attacker may abuse. Public detail indicates the issue could enable remote code execution, so internet-facing or otherwise reachable systems that run the affected component deserve prompt inventory and remediation. Confirm exact product scope, builds, and fixes against the vendor advisory.

IKE is commonly used in IPsec VPN and related key-exchange paths on Windows environments. A memory-corruption flaw in that path matters because successful abuse can undermine the host that terminates or processes IKE traffic, with impact depending on deployment and exposure. Ransomware use is not documented for this CVE in the provided facts.

How it works

This issue is classified as CWE-415 (double free): memory is released more than once, which can corrupt allocator state. In services that parse or process network protocol data, a double free often follows attacker-influenced input that drives an error or cleanup path twice. For Microsoft IKE Service Extensions, the CISA summary states the double free could enable remote code execution. That typically means a remote party who can deliver crafted IKE-related traffic to a vulnerable service may crash the process or, in worse cases, achieve code execution in the service’s context—without needing to invent packet layouts or exploit steps here. Exact preconditions (authentication requirements, which IKE modes or extensions, privilege level) must be taken from the vendor advisory rather than assumed.

Defenders should treat this as a network-facing memory-safety defect in a cryptographic key-exchange stack component: prioritize hosts that accept IKE/IPsec from untrusted networks, then broaden to any internal systems still running the affected extensions.

Am I affected? How to find it in your systems

The affected technology is Microsoft Internet Key Exchange (IKE) Service Extensions—functionality associated with Windows IPsec/IKE rather than a separate third-party appliance. Typical locations include Windows servers and clients acting as VPN gateways, remote-access endpoints, or site-to-site IPsec peers, including roles where the IKE service and related extensions are installed or enabled.

How to remediate

Patch first. Apply the Microsoft update that addresses CVE-2026-33824 for Internet Key Exchange (IKE) Service Extensions exactly as named in the vendor advisory, and verify installation across all applicable SKUs and roles. Align rollout with CISA’s direction to apply mitigations per vendor instructions and BOD 26-04 risk-based prioritization, including cloud or hosted Windows instances your organization controls. If mitigations are unavailable for a given use, CISA notes discontinuing use of the product as a path—evaluate that only where the advisory and your architecture leave no safe option.

If you can't patch immediately

Compensating controls reduce—not eliminate—risk for a remote double-free in an IKE-related service until the vendor fix is installed.

If your data may have been exposed

Actively exploited vulnerabilities can lead to host compromise and follow-on data theft even when ransomware use is not documented for this CVE. If IKE-facing systems were unpatched and reachable, treat them as potentially compromised: isolate, collect volatile and disk evidence per your IR plan and CISA forensics triage requirements, credential-rotate trust material tied to the host (machine and admin secrets, VPN PSKs/certificates as appropriate), and hunt laterally from that foothold. For personal or workforce email accounts that may appear in unrelated breach corpora, you can run a free exposure scan of their email to check known breach data, then enforce password changes and MFA where exposures are confirmed.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Internet Key Exchange (IKE) Service Extensions
WeaknessCWE-415
Added to CISA KEVAug 18, 2026
Federal patch deadlineAug 21, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities