type: cve ยท created: 2026-08-19 ยท updated: 2026-08-19 ยท tags: [cve, microsoft, ike, kev, exploited] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, critical-infrastructure] ยท au_impact: true
CVE-2026-33824
CVE-2026-33824 is a vulnerability in Microsoft Internet Key Exchange (IKE) service extensions, added to the CISA Known Exploited Vulnerabilities (KEV) catalogue on 18 August 2026.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-33824 |
| Type | Exploited-in-the-wild (KEV) |
| Product | Microsoft IKE service extensions |
| KEV added | 2026-08-18 (BOD 26-04 โ 14-day federal remediation) |
| Source | CISA โ Tier 1/4 |
The KEV addition signals confirmed exploitation in the wild of Microsoft's IKE/IPsec stack โ a foundational internet-exposed Windows service. It was added alongside entries for Broadcom VMware vCenter (CVE-2026-59310), Microsoft SharePoint (CVE-2026-55040) and Apple macOS (CVE-2026-65400), and carries the two-week federal remediation obligation under BOD 26-04.