Our automated tracking framework flagged that CISA added CVE-2026-33824 (Microsoft Internet Key Exchange (IKE) Service Extensions) to the Known Exploited Vulnerabilities (KEV) catalog on August 19, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.

What CISA Reported

CISA describes the flaw as follows: “Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.”

Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-33824 by August 21, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.

The Details

CVE CVE-2026-33824
Vendor / product Microsoft Internet Key Exchange (IKE) Service Extensions
Vulnerability Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVSS base score 9.8
Added to KEV August 18, 2026
Days public before listing (NVD → KEV lag) 126
Federal patch deadline August 21, 2026
Known ransomware use No

How This Compares to Microsoft’s Track Record

This one was public for just 126 days before CISA confirmed exploitation — faster than Microsoft’s 560-day median, meaning attackers moved unusually quickly. Microsoft currently ranks #18 on our KEV Lag leaderboard.

Microsoft in the CISA KEV catalog Value
Tracked KEV entries 385
Median lag (public → KEV listing) 560 days
0-day rate (exploited at or before disclosure) 23%
Entries tied to known ransomware campaigns 104

For perspective, the median across all 1670 tracked KEV entries is 268 days — Microsoft’s exploited vulnerabilities are flagged slower than the catalog average.

Other Recent Microsoft KEV Additions

The most recent Microsoft vulnerabilities CISA has confirmed as actively exploited, from our tracker:

CVE Product Added to KEV Lag (days) Ransomware
CVE-2026-55040 SharePoint August 18, 2026 35 No
CVE-2026-68820 Windows Ancillary Function Driver for WinSock August 11, 2026 0 No
CVE-2026-50522 SharePoint July 22, 2026 8 No
CVE-2026-58644 SharePoint July 16, 2026 2 No
CVE-2026-56155 Active Directory Federation Services July 14, 2026 0 No

What This Means for Defenders

CISA has added CVE-2026-33824 to its KEV catalog, a vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions with a CVSS base score of 9.8. Federal agencies must patch this critical vulnerability by August 21, 2026, just three days after its KEV listing on August 18, 2026. All organizations leveraging Microsoft IKE for secure communications should also prioritize patching.

The vulnerability was public for 126 days before its KEV addition. Despite no confirmed ransomware use, the high CVSS score and CISA’s KEV inclusion signal a severe risk. Patching before the August 21 deadline is critical to prevent potential network compromise.

If immediate patching isn’t feasible, restrict access to IKE services, apply network segmentation, and monitor for unusual activity. Review firewall rules and intrusion detection/prevention systems to limit exposure and detect exploit attempts. Organizations should also hunt for any potential exploitation that may have occurred during the 126-day window.

Related Coverage

How We Track This

This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.