Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

Published July 30, 2026 CVE-2026-33824

This is a critical flaw in Windows' IKE (Internet Key Exchange) service that lets attackers run malicious code on your PC just by sending specially crafted network requests. It affects the core security layer used by VPNs, remote work tools, and encrypted connections.

Severity
CriticalCVSS 3.1 · 9.8
Fix
Update availableFix recorded on Aug 26, 2026
Affected versions
10.0.14393.0 to before 10.0.14393.9060; 10.0.17763.0 to before 10.0.17763.8644; 10.0.19044.0 to before 10.0.19044.7184+14 more
Weakness
CWE-415Double Free
Exploit likelihood
73% in 30 daysEPSS, higher than 99% of known flaws
Affects
Windows 10 Version 1607+16 more
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Aug 18, 2026
Federal fix deadline
Aug 21, 2026

How it works

The public report says a flaw in Microsoft version lets attackers get in, but it does not name an exact affected version.

What to do

Check your Windows version by typing 'winver' in the Start menu and pressing Enter. If you're on Windows 10 or Server 2016, 2022 without the June 2026 security update, you're at risk.

Install the June 2026 security update for Windows 10/Server 2016, 2022 from Windows Update (the version screen.

Technical details

Affected software: Windows 10 Version 1607by Microsoft, Windows 10 Version 1809by Microsoft, Windows 10 Version 21H2by Microsoft, Windows 10 Version 22H2by Microsoft, Windows 11 version 22H3by Microsoft, Windows 11 Version 23H2by Microsoft, Windows 11 Version 24H2by Microsoft, Windows 11 Version 25H2by Microsoft, Windows 11 version 26H1by Microsoft, Windows Server 2016by Microsoft, Windows Server 2016 (Server Core installation)by Microsoft, Windows Server 2019by Microsoft, Windows Server 2019 (Server Core installation)by Microsoft, Windows Server 2022by Microsoft, Windows Server 2022, 23H2 Edition (Server Core installation)by Microsoft, Windows Server 2025by Microsoft, Windows Server 2025 (Server Core installation)by Microsoft

Serial Number: AV26-804 Date: August 11, 2026 Updated: August 27, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows App Installer Application Insights Profiler Azure Active Directory Azure Confidential Ledger Azure CycleCloud Azure Kubernetes Service Azure Logic Apps Azure Monitor Agent Linux Extension Azure SQL Database Azure SQL Managed Instance Azure SRE Agent Azure Service Bus Azure Storage Explorer Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Admin Center Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Defender for Endpoint for Mac Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Business Central 2024 Microsoft Dynamics 365 Business Central 2026 Microsoft Dynamics 365 Business Central Release Wave 1 2025 Microsoft Dynamics 365 Business Central Release Wave 2 2025 Microsoft Entra Connect Microsoft Entra ID Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 Microsoft Outlook 2016 Microsoft Planetary Computer Pro (GeoCatalog) Microsoft Power Apps Microsoft PowerPoint 2016 Microsoft Purview eDiscovery Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Online Microsoft SharePoint Server 2019 Microsoft SharePoint Server Subscription Edition Microsoft Teams Microsoft Teams for Android Microsoft Teams for iOS Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Microsoft Visual Studio Code CoPilot Chat Extension Microsoft Word 2016 OneDrive for MacOS Power BI Report Server PowerShell 7.4 PowerShell 7.5 PowerShell 7.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator