CVE-2026-33824

Analyzed
Published: 14 Apr 2026, 16:58
Last modified:19 Aug 2026, 03:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
77.9% CRITICAL
78% probability +22.05%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Apr 2026, 16:58
Published
Vulnerability first disclosed
18 Aug 2026, 00:00
Added to CISA KEV
Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
19 Aug 2026, 03:55
Last Modified
Vulnerability information updated
21 Aug 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 77.90% Percentile: 100%

Techniques & Countermeasures

  • CWE-415Double Free

    The product calls free() twice on the same memory address.

Affected Systems

  • microsoftwindows_10_1607

    < 10.0.14393.9060

  • microsoftwindows_10_1809

    < 10.0.17763.8644

  • microsoftwindows_10_21h2

    < 10.0.19044.7184

  • microsoftwindows_10_22h2

    < 10.0.19045.7184

  • microsoftwindows 10 version 1607

    ≥ 10.0.14393.0, < 10.0.14393.9060

  • microsoftwindows 10 version 1809

    ≥ 10.0.17763.0, < 10.0.17763.8644

  • microsoftwindows 10 version 21h2

    ≥ 10.0.19044.0, < 10.0.19044.7184

  • microsoftwindows 10 version 22h2

    ≥ 10.0.19045.0, < 10.0.19045.7184

  • microsoftwindows_11_23h2

    < 10.0.22631.6936

  • microsoftwindows_11_24h2

    < 10.0.26100.8246

  • microsoftwindows_11_25h2

    < 10.0.26200.8246

  • microsoftwindows_11_26h1

    < 10.0.28000.1836

  • microsoftwindows 11 version 22h3

    ≥ 10.0.22631.0, < 10.0.22631.6936

  • microsoftwindows 11 version 23h2

    ≥ 10.0.22631.0, < 10.0.22631.6936

  • microsoftwindows 11 version 24h2

    ≥ 10.0.26100.0, < 10.0.26100.32690 | ≥ 10.0.26100.0, < 10.0.26100.8246

  • microsoftwindows 11 version 25h2

    ≥ 10.0.26200.0, < 10.0.26200.8246

  • microsoftwindows 11 version 26h1

    ≥ 10.0.28000.0, < 10.0.28000.1836

  • microsoftwindows server 2016

    ≥ 10.0.14393.0, < 10.0.14393.9060 | < 10.0.14393.9060

  • microsoftwindows server 2016 (server core installation)

    ≥ 10.0.14393.0, < 10.0.14393.9060

  • microsoftwindows server 2019

    ≥ 10.0.17763.0, < 10.0.17763.8644 | < 10.0.17763.8644

  • microsoftwindows server 2019 (server core installation)

    ≥ 10.0.17763.0, < 10.0.17763.8644

  • microsoftwindows server 2022

    ≥ 10.0.20348.0, < 10.0.20348.5020 | < 10.0.20348.5020

  • microsoftwindows_server_2022_23h2

    < 10.0.25398.2274

  • microsoftwindows server 2022, 23h2 edition (server core installation)

    ≥ 10.0.25398.0, < 10.0.25398.2274

  • microsoftwindows server 2025

    ≥ 10.0.26100.0, < 10.0.26100.32690 | < 10.0.26100.32690

  • microsoftwindows server 2025 (server core installation)

    ≥ 10.0.26100.0, < 10.0.26100.32690

References (3)