The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Windows vulnerability to its Known Exploited Vulnerabilities catalog after confirming it is already being used in real-world attacks, according to a report from BleepingComputer. The flaw, tracked as CVE-2026-33824, sits in the Internet Key Exchange Service Extensions that Windows uses to negotiate VPN and IPsec connections.
The bug is a "double free" memory-corruption issue that lets an attacker with no credentials at all execute code on a vulnerable machine simply by sending malformed packets to UDP ports 500 or 4500 — the ports IKE uses to establish secure tunnels. It affects every currently supported release of Windows 10, Windows 11 and Windows Server, and because remote-access VPN endpoints are, by design, reachable from the open internet, security researchers have flagged it as an urgent perimeter risk rather than one that depends on an attacker already being inside a network.
A Three-Day Clock for Federal Agencies
CISA added CVE-2026-33824 to its exploited-vulnerabilities catalog on August 18 and, under Binding Operational Directive 26-04, gave federal civilian agencies until August 21 to patch or otherwise secure affected systems — a compressed timeline the agency reserves for flaws it considers to be under active, meaningful exploitation. The order applies directly only to federal networks, but CISA also urged all network defenders, in government and industry alike, to treat the patch as urgent.
An unauthenticated attacker could send specially crafted packets to a Windows machine.
Microsoft security advisory
For organizations that cannot immediately install the update, Microsoft's guidance is to block inbound UDP traffic on ports 500 and 4500 on any system that doesn't use IKE at all, or, where IKE is required, to restrict inbound access to a known list of peer addresses rather than leaving the service open to any host on the internet.
The vulnerability arrives as part of a busier-than-usual week in CISA's exploited-vulnerabilities catalog: the agency also added actively exploited flaws affecting Apple macOS, Microsoft SharePoint and Broadcom's VMware vCenter within the same stretch, according to a roundup from Security Affairs, suggesting attackers are working through a backlog of freshly disclosed enterprise software bugs in parallel.
Microsoft has not yet updated its own advisory to explicitly confirm in-the-wild exploitation, even as CISA's listing makes clear that attacks are already underway. Security teams running VPN infrastructure on Windows are being advised not to wait for that confirmation before patching or applying the port-blocking workaround.