Knox CVE Database
/
CVE-2026-33824
Critical
9.8

CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Added to the CISA KEV catalog:
August 18, 2026

Overview

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

Vulnerability details

Affected vendor
Microsoft
Affected product
Internet Key Exchange (IKE) Service Extensions
Weakness type (CWE)
CWE-415

The Windows Internet Key Exchange (IKE) Extension service contains a double-free vulnerability (CWE-415) in its processing of IKE protocol messages. A double-free occurs when the same heap memory region is freed twice, corrupting allocator metadata in a way that can redirect execution flow. Because the IKE service processes network packets before any authentication occurs, the vulnerable code path is reachable by any host that can send UDP traffic to the target, making this a pre-authentication, network-exposed memory corruption flaw rated Critical by Microsoft.


An unauthenticated attacker sends specially crafted IKE protocol packets to a target system reachable on the IKE port (typically UDP 500 or 4500). The malformed packets trigger the double-free condition in the IKE Extension service, corrupting heap memory in a manner that can redirect execution to attacker-controlled code. Successful exploitation yields remote code execution with the privileges of the IKE service process, resulting in full confidentiality, integrity, and availability impact. No user interaction is required. Unit 42 has reported this vulnerability was targeted by an AI-assisted autonomous attack campaign.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor Windows Security and System event logs for unexpected crashes or restarts of the IKE service (ikeext.dll / IKEEXT service), particularly fault-bucket entries or application error events with no corresponding administrative action.
  • Alert on inbound UDP traffic to ports 500 and 4500 from sources outside established VPN peer or site-to-site tunnel configurations, especially high-volume or malformed-packet sequences that do not complete a valid IKE negotiation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 21, 2026

Additional hardening

  • Apply the Microsoft security update bringing Windows 10 1607 and Server 2016/2019 to build 10.0.14393.9060 or 10.0.17763.8644 respectively, and Windows 11 / Server 2025 to the fixed builds listed in the vendor advisory under References.
  • Restrict inbound UDP 500 and 4500 traffic at perimeter and host-based firewalls to known, authorized VPN peer addresses only, eliminating exposure to unauthenticated attackers on the open internet.
  • Disable the IKEEXT service on Windows systems that do not require IPsec or IKE-based VPN functionality, removing the attack surface entirely on those hosts.
  • Audit network segmentation to confirm that IKE-capable hosts are not directly reachable from untrusted networks; place them behind a firewall or VPN concentrator that terminates IKE sessions before forwarding.

Key dates

Published (NVD)
April 14, 2026
Added to CISA KEV
August 18, 2026
Remediation deadline
August 21, 2026
Last updated
August 19, 2026

References

Frequently asked questions

Does CVE-2026-33824 affect my FedRAMP authorization?

If Microsoft Internet Key Exchange (IKE) Service Extensions runs inside your authorization boundary, yes, CVE-2026-33824 affects your FedRAMP authorization. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 21, 2026. An unpatched KEV inside the boundary is a finding your assessor and sponsoring agency will raise. You must remediate it or formally document a mitigation before that deadline.

How does Knox help me handle CVE-2026-33824?

Knox does not patch your software. Remediating Microsoft Internet Key Exchange (IKE) Service Extensions is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-33824. Because monitoring runs continuously, exposure surfaces during ongoing review rather than only when an assessor flags it at a scheduled assessment. That difference gives your team time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-33824 isn't remediated by August 21, 2026?

Missing the August 21, 2026 deadline turns CVE-2026-33824 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization clean and preserves the agency relationship.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting