Hackers have started using a critical Windows vulnerability that allows you to remotely run code on a computer without an account and any action on the part of the user. The U.S. Cybersecurity and Infrastructure Protection Agency (CISA) confirmed the real attacks and required the U.S. federal agencies to establish corrections.
The vulnerability has received the CVE-2026-33824 (10.0 Critical) ID and touches on the supported versions of Windows 10, Windows 11, and Windows Server. Microsoft fixed the error back in April 2026. The problem is in the IKE key exchange service extensions that Windows uses when installing secure network connections.
The vulnerability arose from the fact that memory is released twice. For an attack, an attacker does not need credentials or prior access to the system. It is enough to send specially prepared network packages to a computer with IKEv2 enabled. As a result, the attacker can achieve remote execution of its code.
The IKE protocol data is transmitted through UDP ports 500 and 4500. Microsoft's extensions for the IKE protocol add a number of features, including denial-of-service protection, work through network address conversion, cryptographically generated address authentication, and node-free nodes compatibility without IPsec support.
CISA on August 18 entered CVE-2026-33824 into the catalog of vulnerabilities that are already used by intruders. Details of the attacks, information about the purposes and tools used by the agency have not yet been disclosed. Microsoft also did not add a confirmation mark to its bulletin at the time of publication.
U.S. federal civil authorities ordered the vulnerability to be eliminated within three days. CISA also recommends that all organizations install the April security update as soon as possible. Microsoft advises, if it is not possible to immediately update, block incoming traffic through UDP ports 500 and 4500 on systems where IKE is not needed. If the service is used, the firewall should be configured to receive connections only from known nodes.
The danger of CVE-2026-33824 reinforces several factors at once: the attack passes through the network, does not require authentication and is already applied in practice. Windows systems that are available through specified UDP ports and have not received April fixes, the update is better installed without delay.
The vulnerability has received the CVE-2026-33824 (10.0 Critical) ID and touches on the supported versions of Windows 10, Windows 11, and Windows Server. Microsoft fixed the error back in April 2026. The problem is in the IKE key exchange service extensions that Windows uses when installing secure network connections.
The vulnerability arose from the fact that memory is released twice. For an attack, an attacker does not need credentials or prior access to the system. It is enough to send specially prepared network packages to a computer with IKEv2 enabled. As a result, the attacker can achieve remote execution of its code.
The IKE protocol data is transmitted through UDP ports 500 and 4500. Microsoft's extensions for the IKE protocol add a number of features, including denial-of-service protection, work through network address conversion, cryptographically generated address authentication, and node-free nodes compatibility without IPsec support.
CISA on August 18 entered CVE-2026-33824 into the catalog of vulnerabilities that are already used by intruders. Details of the attacks, information about the purposes and tools used by the agency have not yet been disclosed. Microsoft also did not add a confirmation mark to its bulletin at the time of publication.
U.S. federal civil authorities ordered the vulnerability to be eliminated within three days. CISA also recommends that all organizations install the April security update as soon as possible. Microsoft advises, if it is not possible to immediately update, block incoming traffic through UDP ports 500 and 4500 on systems where IKE is not needed. If the service is used, the firewall should be configured to receive connections only from known nodes.
The danger of CVE-2026-33824 reinforces several factors at once: the attack passes through the network, does not require authentication and is already applied in practice. Windows systems that are available through specified UDP ports and have not received April fixes, the update is better installed without delay.