THREAT OPS › CVEs › CVE-2026-33824
CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
Vulnerability details
- Affected productsInternet Key Exchange (IKE) Service Extensions
- KEV remediation due2026-08-21
Related reporting
- August 2026 CVE Landscaperecordedfuture
- Windows IKE CVE-2026-33824 Added to CISA KEVsocradar_blog
- [NVD] CVE-2026-33824 (CRITICAL 9.8) — Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.nvd
- CISA Adds Four Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2026-33824 — Microsoft Internet Key Exchange (IKE) Service Extensions: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerabilitycisa_kev
- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposuretenable
- July 2026 CVE Landscaperecordedfuture
- The April 2026 Security Update Reviewzdi_blog
- CVE-2026-33824: Remote Code Execution in Windows IKEv2zdi_blog