Morning Edition · №
Cybersecurity NEW YORK

CISA Orders Emergency Fix for Windows VPN Flaw Under Active Attack

A critical, unauthenticated remote-code-execution bug in Windows' IKE VPN component is already being exploited, pushing federal agencies toward a three-day patch deadline.

CISA Orders Emergency Fix for Windows VPN Flaw Under Active Attack
— Photograph: Sasun Bughdaryan / Unsplash
SHARE X f in ⧉

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Windows vulnerability to its Known Exploited Vulnerabilities catalog after confirming it is already being used in real-world attacks, according to a report from BleepingComputer. The flaw, tracked as CVE-2026-33824, sits in the Internet Key Exchange Service Extensions that Windows uses to negotiate VPN and IPsec connections.

The bug is a "double free" memory-corruption issue that lets an attacker with no credentials at all execute code on a vulnerable machine simply by sending malformed packets to UDP ports 500 or 4500 — the ports IKE uses to establish secure tunnels. It affects every currently supported release of Windows 10, Windows 11 and Windows Server, and because remote-access VPN endpoints are, by design, reachable from the open internet, security researchers have flagged it as an urgent perimeter risk rather than one that depends on an attacker already being inside a network.

A Three-Day Clock for Federal Agencies

CISA added CVE-2026-33824 to its exploited-vulnerabilities catalog on August 18 and, under Binding Operational Directive 26-04, gave federal civilian agencies until August 21 to patch or otherwise secure affected systems — a compressed timeline the agency reserves for flaws it considers to be under active, meaningful exploitation. The order applies directly only to federal networks, but CISA also urged all network defenders, in government and industry alike, to treat the patch as urgent.

An unauthenticated attacker could send specially crafted packets to a Windows machine.

Microsoft security advisory

For organizations that cannot immediately install the update, Microsoft's guidance is to block inbound UDP traffic on ports 500 and 4500 on any system that doesn't use IKE at all, or, where IKE is required, to restrict inbound access to a known list of peer addresses rather than leaving the service open to any host on the internet.

The vulnerability arrives as part of a busier-than-usual week in CISA's exploited-vulnerabilities catalog: the agency also added actively exploited flaws affecting Apple macOS, Microsoft SharePoint and Broadcom's VMware vCenter within the same stretch, according to a roundup from Security Affairs, suggesting attackers are working through a backlog of freshly disclosed enterprise software bugs in parallel.

Microsoft has not yet updated its own advisory to explicitly confirm in-the-wild exploitation, even as CISA's listing makes clear that attacks are already underway. Security teams running VPN infrastructure on Windows are being advised not to wait for that confirmation before patching or applying the port-blocking workaround.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →