CVE Tools
Back to feed
Exploited in the wild Windows rce Microsoft network-edge

Critical RCE flaw in Windows IKE Extension now actively exploited

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has confirmed that threat actors are actively exploiting a critical remote code execution vulnerability in the Windows IKE Service Extensions component, tracked as CVE-2026-33824. This double-free flaw affects all supported versions of Windows 10, Windows 11, and Windows Server, allowing unauthenticated attackers to achieve code execution by sending maliciously crafted packets over UDP ports 500 or 4500. Microsoft addressed the issue during the April 2026 Patch Tuesday cycle, and security teams should apply the relevant updates immediately or restrict inbound traffic on those UDP ports if immediate patching is not possible.