EXPOSURES › CVE-2026-33824
CVE-2026-33824
HIGH ⌖ ON CISA KEV · EXPLOITEDA double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild.
This double free flaw in Microsoft's IKE Service Extensions enables remote code execution, meaning attackers can execute arbitrary commands on affected systems without prior access. For DIB organizations, this represents a critical exposure where unpatched systems could be compromised remotely, leading to data breaches or system takeover. Organizations must ensure this CVE is patched immediately and monitor for exploitation attempts.
Shame score — A double free vulnerability enabling remote code execution that is actively exploited in the wild demonstrates severe negligence in patch management and vulnerability handling.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |