Skip to content
COOEY

EXPOSURES › CVE-2026-33824

CVE-2026-33824

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-18 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-33824 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild.

This double free flaw in Microsoft's IKE Service Extensions enables remote code execution, meaning attackers can execute arbitrary commands on affected systems without prior access. For DIB organizations, this represents a critical exposure where unpatched systems could be compromised remotely, leading to data breaches or system takeover. Organizations must ensure this CVE is patched immediately and monitor for exploitation attempts.

Shame score — A double free vulnerability enabling remote code execution that is actively exploited in the wild demonstrates severe negligence in patch management and vulnerability handling.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized