CISA Warns of Active Exploitation in Windows IKE Service RCE Flaw
The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has issued an urgent warning regarding a critical remote code execution (RCE) vulnerability in the **Windows Internet Key Exchange (IKE) Service Extensions** component. Tracked as **CVE-2026-33824**, this flaw is now being actively exploited in the wild, posing significant risks to unpatched Windows systems.
# CISA Warns of Active Exploitation in Windows IKE Service RCE Flaw

The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has sounded the alarm, indicating that attackers are actively exploiting a critical-severity remote code execution (RCE) vulnerability within the **Windows Internet Key Exchange (IKE) Service Extensions** component.
### Understanding the Vulnerability: CVE-2026-33824
This specific component, also known as **MS-IKEE**, enhances the IKE Protocol with features like authentication via cryptographically generated addresses (CGAs) and denial-of-service protection. The vulnerability, identified as **CVE-2026-33824**, affects all supported versions of **Windows 10**, **Windows 11**, and **Windows Server**.
Attackers can leverage this flaw without requiring any privileges, simply by sending maliciously crafted packets to unpatched Windows systems. The attack vector primarily utilizes UDP ports 500 or 4500.
**Microsoft** addressed this RCE vulnerability during its April 2026 Patch Tuesday, describing it as a "double free in Windows IKE Extension" that allows an "unauthorized attacker to execute code over a network."
### Microsoft's Advisory and Mitigation
According to **Microsoft**'s advisory, "An unauthenticated attacker could send specially crafted packets to a Windows machine with Internet Key Exchange (IKE) version 2 enabled, which could enable remote code execution."
For organizations unable to apply the security update immediately, **Microsoft** recommends blocking inbound traffic through UDP ports 500 and 4500 on systems not utilizing IKE. Alternatively, firewall rules can be configured to permit inbound traffic only from known peer addresses where IKE is in use.
### Active Exploitation Confirmed by CISA
Despite **Microsoft** not yet updating its advisory to reflect active exploitation, **CISA** has added **CVE-2026-33824** to its catalog of actively exploited vulnerabilities. This move mandates **U.S. Federal Civilian Executive Branch (FCEB)** agencies to patch their affected devices within three days, in accordance with Binding Operational Directive 26-04.
**CISA** emphasized the severity of the situation, stating, "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise."
While BOD 26-04 primarily targets government agencies, **CISA** strongly urges all network defenders to prioritize patching **CVE-2026-33824** to mitigate ongoing attacks.
### Broader Context of Exploited Vulnerabilities
This incident follows a series of warnings from **CISA** regarding actively exploited flaws. Recently, **CISA** confirmed that a high-severity **Windows Task Host** vulnerability, previously flagged as exploited in April, is now being abused in ransomware attacks. Furthermore, **CISA** warned that ransomware operations have begun exploiting a **Microsoft SharePoint RCE** vulnerability following confirmation of in-the-wild exploitation earlier in July.
Since November 2021, **CISA** has identified 385 actively exploited vulnerabilities across various **Microsoft** products, with 112 of these also being leveraged by ransomware gangs.