What CISA Confirmed on August 18
CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog on August 18, 2026, confirming that a double-free vulnerability in Windows IKE Service Extensions, the component that handles IKEv2/IPsec VPN connections, is being actively exploited in the wild. The flaw carries a CVSS score of 9.8 out of 10 and requires no authentication, so an attacker who can reach a vulnerable server over the network can trigger it without a password, a certificate, or any prior foothold.
| Milestone | Date |
|---|---|
| Microsoft patch released | April 2026 |
| CVSS score | 9.8 out of 10 |
| Added to CISA KEV catalog | August 18, 2026 |
| Federal remediation deadline | August 21, 2026 (passed) |
The vulnerability sits on UDP ports 500 and 4500, the ports IKEv2/IPsec uses to negotiate and maintain a VPN tunnel, and it hits every supported version of Windows Server, Windows 10 and Windows 11 that has IKEv2/IPsec VPN exposed to the internet. CISA's alert arrived inside a four-CVE batch that also covered a macOS Screen Sharing flaw and a VMware vCenter path-traversal bug, but the Windows IKE flaw carries the clearest exposure of the four, and CISA set August 21, 2026 as the remediation deadline for US federal agencies, a deadline that had already passed by the time this reporting closed.
How Unit 42 Caught the Callbacks
Unit 42, Palo Alto Networks' threat intelligence arm, reported observing a Chinese-speaking threat actor sending hands-on-keyboard reverse-shell callbacks from three separate IKE VPN endpoints. A reverse shell dials outward from the compromised machine to attacker infrastructure instead of waiting for an inbound connection, which is exactly why it survives the inbound-facing firewall rules most perimeter security is built around; the compromised VPN server simply looks, to a lot of monitoring setups, like it is making an outbound connection of its own accord.
Hands-on-keyboard activity means a human operator was interactively issuing commands through the shell rather than running a fully automated script, a level of manual effort that signals the target was worth direct attention rather than a mass, indiscriminate sweep. BleepingComputer, SentinelOne's CVE database and the Zero Day Initiative have each corroborated the core technical details since CISA's alert, and gbhackers.com's reporting on the Unit 42 research adds the reverse-shell detail that turns a generic double-free bug into a documented, in-progress intrusion.
Patched in April Is Not the Same Claim as Safe Today
Microsoft shipped a fix for CVE-2026-33824 in April 2026, five full months before CISA confirmed active exploitation and added the flaw to the KEV catalog. That gap is the story underneath the story: a patch existing since April tells you Microsoft did its part, but it tells you nothing about whether every internet-facing VPN concentrator in a given organization actually received that patch, and it tells you even less about whether anyone was watching those endpoints for the kind of outbound reverse-shell traffic Unit 42 found.
"We patched it months ago" and "we are safe today" are two separate claims, not one, and treating them as interchangeable is exactly how a five-month-old fix ends up sitting next to a live, hands-on-keyboard intrusion. A VPN concentrator is a natural patch straggler: it is often managed by a network team rather than the endpoint-patching team, sits outside routine vulnerability scans built around workstation-style update cycles, and cannot always be rebooted onto a new build without a planned maintenance window that competes with uptime commitments. Segmentation that limits what a compromised VPN server can reach, and monitoring that flags anomalous egress from that server, are the two checks that catch what "the patch shipped in April" cannot.
What to Check This Week
IT and security teams should confirm the patch rather than assume it: they need to verify that every Windows Server, Windows 10 and Windows 11 system with IKEv2/IPsec VPN enabled and reachable from the internet actually received Microsoft's April 2026 update, not just that the update exists in the catalog. A VPN gateway commissioned or re-imaged after the patch's release, or one managed by a third party, is exactly the kind of instance that quietly misses a rollout everyone else assumes is complete.
Then they should check what happens after the patch is confirmed: whether UDP 500/4500 traffic to that concentrator is segmented from the rest of the network so a single compromised gateway cannot become a path to everything behind it, and whether outbound connections from the VPN server itself are monitored for the kind of reverse-shell callback Unit 42 documented. This is exactly the profile that CISA's KEV catalog exists to flag, and the same profile the UK's National Cyber Security Centre treats as high-priority guidance territory for any operator running internet-facing VPN infrastructure.
Read next: 9.8 CVSS: macOS VNC Flaw Now Mining Monero | Langflow's Two-Call Chain Handed Root to 295 Attackers



