Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability
This is a critical flaw in Windows' IKE (Internet Key Exchange) service that lets attackers run malicious code on your PC just by sending specially crafted network requests. It affects the core security layer used by VPNs, remote work tools, and encrypted connections.
- Severity
- CriticalCVSS 3.1 · 9.8
- Fix
- Update availableFix recorded on Aug 26, 2026
- Affected versions
- 10.0.14393.0 to before 10.0.14393.9060; 10.0.17763.0 to before 10.0.17763.8644; 10.0.19044.0 to before 10.0.19044.7184+14 more
- Weakness
- CWE-415Double Free
- Exploit likelihood
- 73% in 30 daysEPSS, higher than 99% of known flaws
- Affects
- Windows 10 Version 1607+16 more
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Aug 18, 2026
- Federal fix deadline
- Aug 21, 2026
How it works
The public report says a flaw in Microsoft version lets attackers get in, but it does not name an exact affected version.
What to do
Check your Windows version by typing 'winver' in the Start menu and pressing Enter. If you're on Windows 10 or Server 2016, 2022 without the June 2026 security update, you're at risk.
Install the June 2026 security update for Windows 10/Server 2016, 2022 from Windows Update (the version screen.
Technical details
Affected software: Windows 10 Version 1607by Microsoft, Windows 10 Version 1809by Microsoft, Windows 10 Version 21H2by Microsoft, Windows 10 Version 22H2by Microsoft, Windows 11 version 22H3by Microsoft, Windows 11 Version 23H2by Microsoft, Windows 11 Version 24H2by Microsoft, Windows 11 Version 25H2by Microsoft, Windows 11 version 26H1by Microsoft, Windows Server 2016by Microsoft, Windows Server 2016 (Server Core installation)by Microsoft, Windows Server 2019by Microsoft, Windows Server 2019 (Server Core installation)by Microsoft, Windows Server 2022by Microsoft, Windows Server 2022, 23H2 Edition (Server Core installation)by Microsoft, Windows Server 2025by Microsoft, Windows Server 2025 (Server Core installation)by Microsoft
Serial Number: AV26-804 Date: August 11, 2026 Updated: August 27, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows App Installer Application Insights Profiler Azure Active Directory Azure Confidential Ledger Azure CycleCloud Azure Kubernetes Service Azure Logic Apps Azure Monitor Agent Linux Extension Azure SQL Database Azure SQL Managed Instance Azure SRE Agent Azure Service Bus Azure Storage Explorer Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Admin Center Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Defender for Endpoint for Mac Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Business Central 2024 Microsoft Dynamics 365 Business Central 2026 Microsoft Dynamics 365 Business Central Release Wave 1 2025 Microsoft Dynamics 365 Business Central Release Wave 2 2025 Microsoft Entra Connect Microsoft Entra ID Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 Microsoft Outlook 2016 Microsoft Planetary Computer Pro (GeoCatalog) Microsoft Power Apps Microsoft PowerPoint 2016 Microsoft Purview eDiscovery Microsoft SharePoint Enterprise Server 2016 Microsoft SharePoint Online Microsoft SharePoint Server 2019 Microsoft SharePoint Server Subscription Edition Microsoft Teams Microsoft Teams for Android Microsoft Teams for iOS Microsoft Visual Studio 2022 Microsoft Visual Studio 2026 Microsoft Visual Studio Code CoPilot Chat Extension Microsoft Word 2016 OneDrive for MacOS Power BI Report Server PowerShell 7.4 PowerShell 7.5 PowerShell 7.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- nvd.nist.gov · CVE-2026-33824 vdb entry
- msrc.microsoft.com · CVE-2026-33824 Vendor Advisory
- unit42.paloaltonetworks.com · autonomous-ai-cyber-attack-campaign Third Party Advisory
- cisa.gov · known-exploited-vulnerabilities-catalog US Government Resource CCCS Canada
- cisa.gov · cisa-adds-four-known-exploited-vulnerabilities-catalog CISA Advisory
- msrc.microsoft.com · 2026-Aug CCCS Canada