AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 22 Aug, 12:11

Critical Windows VPN flaw (CVE-2026-33824) under active exploitation

A critical, unauthenticated remote-code-execution flaw in the Windows IKE VPN service is being actively exploited. CISA added it to its Known Exploited Vulnerabilities catalog on August 18 and gave federal agencies until August 21 to patch. Palo Alto Networks says a Chinese-speaking threat actor has been manually exploiting it.

CVE-2026-33824 is a critical, CVSS 9.8 double-free vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions, the component that negotiates VPN connections on Routing and Remote Access servers and IPsec gateways. An unauthenticated attacker can trigger it by sending specially crafted packets to UDP port 500 or 4500, gaining full SYSTEM privileges with no credentials or user interaction required. Microsoft shipped a fix in the April 2026 Patch Tuesday update, but on August 18, 2026 the U.S. Cybersecurity and Infrastructure Security Agency added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to patch by August 21. Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor has been conducting manual operations against known vulnerabilities, including this one. Microsoft says customers who already installed the April update are protected. The gap between the April patch and confirmed August exploitation left a four-month window during which the flaw sat unpatched on internet-facing VPN endpoints.

#cyber
Published on