Vulnerability
Published 2026-08-18
Verified 2026-09-19

Microsoft IKE Service Extensions double-free (CVE-2026-33824)

CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog on 18 August 2026: a double-free in Microsoft Internet Key Exchange (IKE) Service Extensions. Treat internet-reachable IKE as known-exploited and apply Microsoft's update.

Product
Microsoft IKE Service Extensions
Exploited in Australia?
unknown

Primary: NVD · Vendor: CISA KEV · CVE: CVE-2026-33824 · CISA KEV addition notice

vulnerabilities