CISA has warned that attackers are actively exploiting CVE-2026-33824, a critical remote code execution flaw in the Windows IKE Extension that affects supported Windows 10, Windows 11, and Windows Server systems. Microsoft advises immediate patching, or temporary firewall restrictions on UDP ports 500 and 4500, as CISA orders U.S. federal agencies to remediate the issue within three days. #CVE-2026-33824 #WindowsIKEExtension #CISA #Microsoft #Windows10 #Windows11 #WindowsServer
Keypoints
- CVE-2026-33824 is a critical RCE flaw in the Windows IKE Extension.
- The bug lets unauthenticated attackers execute code by sending crafted packets.
- All supported Windows 10, Windows 11, and Windows Server releases are affected.
- Attack traffic can reach systems through UDP ports 500 and 4500.
- CISA has added the flaw to its actively exploited catalog and ordered urgent federal action.