CVE-2026-33824: Microsoft fixes a critical RCE flaw in Windows IKE service extension

20 Aug 2026

Microsoft has recently fixed a critical flaw in its Windows Internet Key Exchange Service Extension component that allowed attackers to execute arbitrary code remotely on the affected Windows systems.

 

Through this blog, we will understand what the critical RCE vulnerability in Windows IKE is about, the threats posed by it, and what organizations should do to defend against it.

About the vulnerabilities

Vendor + components affected 

CVE/CVSS 

About  

Alert regarding Active exploitation   

Affected systems 

Microsoft + Windows Internet Key Exchange (IKE) Service Extension 

 

CVE-2026-33824 / (9.8) (Critical) 

Remote Code Execution Vulnerability  

 

This vulnerability is caused due to a double-free memory corruption issue in the Windows IKE extension. 

August 19, 2026 

  • Windows 10 Version 1607 
  • Windows 10 Version 1809 
  • Windows 10 Version 21H2 
  • Windows 10 Version 22H2 
  • Windows 11 Version 22H3 
  • Windows 11 Version 23H2 
  • Windows 11 Version 24H2 
  • Windows 11 Version 25H2 
  • Windows 11 Version 26H1 
  • Windows Server 2016 
  • Windows Server 2019 
  • Windows Server 2022 
  • Windows Server 2022, 23H2 Edition 
  • Windows Server 2025 

 

Server Core installations of the applicable Windows Server releases are also affected.  

The threat posed by the vulnerability

This vulnerability can be exploited by an unauthenticated attacker who sends specially crafted network packets to an affected Windows system where Internet Key Exchange version 2 (IKEv2) is enabled. 

 

An attacker can exploit the vulnerability to: 

 

  • Execute arbitrary code remotely on vulnerable Windows systems. 
  • Gain control over the affected Windows system without requiring any valid credentials. 
  • Target internet-facing or externally reachable Windows systems using malicious IKE packets. 
  • Cause a compromise of the confidentiality, integrity, and availability of the affected system. 
  • Execute malicious processes with the privileges available to the exploited service. 
  • Establish a persistence mechanism. 
  • Deploy additional malware after gaining code execution. 
  • Laterally move across other systems within the environment. 

Official security guidance

Organizations should identify the affected systems using Microsoft Defender Vulnerability Management or their enterprise vulnerability management platform and verify whether the applicable patch is installed.

 

Examples of vulnerable build thresholds identified in Microsoft’s CVE record include:

 

  • Windows 10 Version 1607: Before 10.0.14393.9060
  • Windows 10 Version 1809: Before 10.0.17763.8644
  • Windows 10 Version 21H2: Before 10.0.19044.7184
  • Windows 10 Version 22H2: Before 10.0.19045.7184
  • Windows 11 Version 23H2: Before 10.0.22631.6936
  • Windows 11 Version 24H2: Before 10.0.26100.8246
  • Windows 11 Version 25H2: Before 10.0.26200.8246
  • Windows 11 Version 26H1: Before 10.0.28000.1836
  • Windows Server 2016: Before 10.0.14393.9060
  • Windows Server 2019: Before 10.0.17763.8644
  • Windows Server 2022: Before 10.0.20348.5020
  • Windows Server 2022, 23H2 Edition: Before 10.0.25398.2274
  • Windows Server 2025: Before 10.0.26100.32690

 

Build numbers should be validated against Microsoft’s current security-update guidance before determining patch compliance, as cumulative updates can change the applicable build level.

SharkStriker’s recommendations

  • Prioritize CVE-2026-33824 for immediate remediation because it is a Critical remote code execution vulnerability with confirmed active exploitation.
  • Identify all Windows systems exposed to untrusted networks.
  • Determine which systems have IKEv2/IPsec enabled.
  • Identify systems accepting inbound UDP 500 and 4500 traffic.
  • Apply the applicable Microsoft security updates as soon as possible.
  • Prioritize Internet-facing Windows servers and systems providing VPN/IPsec functionality.
  • Restrict IKE traffic to trusted peers where operationally feasible.
  • Block UDP 500 and 4500 on systems that do not require IKE functionality.
  • Ensure Microsoft Defender Antivirus and endpoint detection and response protections are enabled.
  • Monitor for suspicious processes, network connections, and post-exploitation activity on affected Windows systems.
  • Validate patch compliance after deployment.
  • Treat unpatched Internet-facing systems as high-priority assets for immediate remediation.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE