CVE-2026-33824 · Critical · CISA KEV

CISA KEV: Microsoft IKE Double Free Enables Remote Code Execution

Threat Engine Auto-Feed · data current as of 2026-08-19

CVE-2026-33824, a double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions, is listed in CISA KEV, indicating active exploitation. This flaw can lead to remote code execution. Its high EPSS score (0.5585, 99th percentile) further underscores the urgency for defensive measures.

  • CVSS:
  • EPSS percentile: 0.98957
  • Exploitation pressure: 84/100 (Critical)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 99th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

A double free vulnerability occurs when a program attempts to release the same block of memory twice. This can corrupt memory, leading to unpredictable behavior, including crashes or, in severe cases, allowing an attacker to execute arbitrary code.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations utilizing Microsoft Internet Key Exchange (IKE) Service Extensions
  • Financial services organizations (targeted by FIN7, LockBit affiliates, APT38)
  • Technology sector organizations (targeted by APT29, Scattered Spider)

Misconfigurations that escalate it

    High-impact scenarios

    • Remote code execution on affected systems, leading to full system compromise
    • Potential for lateral movement within the network after initial compromise
    • Data exfiltration or disruption of critical services if exploited by financially motivated actors or nation-state groups

    Likely adversaries

    • FIN7 — Financial services (Assessed)
    • LockBit affiliates — Financial services (Assessed)
    • APT38 (Lazarus) — Financial services (Assessed)
    • APT29 (Cozy Bear) — Technology (Assessed)
    • Scattered Spider — Technology (Assessed)

    What to do (defensive)

    Detect

    • Monitor for unusual process activity or network connections originating from systems running Microsoft Internet Key Exchange (IKE) Service Extensions.
    • Look for signs of memory corruption or unexpected application crashes related to the IKE service.

    Contain

    • Isolate affected systems from the network to prevent further compromise.

    Patch

    • Apply available security updates from Microsoft for Internet Key Exchange (IKE) Service Extensions immediately.

    Frontier verdict — Critical

    Critical priority due to active exploitation (CISA KEV) and high EPSS score, enabling remote code execution.

    For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.