Hackers Actively Exploit Critical Windows IKE Extension Remote Code Execution Flaw
CISA is warning that hackers are actively exploiting a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions component. The flaw, tracked as CVE-2026-33824, stems from a double free issue and allows unauthenticated attackers to execute code by sending specially crafted packets to unpatched systems over UDP ports 500 or 4500. All supported Windows 10, Windows 11, and Windows Server releases are affected.
Microsoft first addressed the vulnerability during the April 2026 Patch Tuesday, and the company advises security teams that cannot immediately install the update to block inbound traffic on UDP ports 500 and 4500 for systems that do not use IKE. For systems that do rely on IKE, Microsoft recommends configuring firewall rules to permit inbound traffic only from known peer addresses.
CISA has added the flaw to its catalog of actively exploited vulnerabilities and is ordering Federal Civilian Executive Branch agencies to secure affected devices within three days under Binding Operational Directive 26-04. While the directive applies only to government agencies, CISA urges all network defenders to prioritize patching to block ongoing attacks. Microsoft has not yet updated its advisory to flag the flaw as exploited and has not responded to requests for further details.