Our automated tracking framework flagged that CISA added CVE-2026-33824 (Microsoft Internet Key Exchange (IKE) Service Extensions) to the Known Exploited Vulnerabilities (KEV) catalog on August 19, 2026. A KEV listing is CISA’s official confirmation that the flaw is being exploited in the wild — U.S. federal agencies must patch it by a fixed deadline. Here is what our data shows.
What CISA Reported
CISA describes the flaw as follows: “Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.”
Under Binding Operational Directive rules, U.S. federal agencies must remediate CVE-2026-33824 by August 21, 2026 — a 3-day window. Private organizations are not bound by the deadline, but CISA treats it as the benchmark for how urgently a confirmed-exploited flaw should be patched.
The Details
| CVE | CVE-2026-33824 |
| Vendor / product | Microsoft Internet Key Exchange (IKE) Service Extensions |
| Vulnerability | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability |
| CVSS base score | 9.8 |
| Added to KEV | August 18, 2026 |
| Days public before listing (NVD → KEV lag) | 126 |
| Federal patch deadline | August 21, 2026 |
| Known ransomware use | No |
How This Compares to Microsoft’s Track Record
This one was public for just 126 days before CISA confirmed exploitation — faster than Microsoft’s 560-day median, meaning attackers moved unusually quickly. Microsoft currently ranks #18 on our KEV Lag leaderboard.
| Microsoft in the CISA KEV catalog | Value |
|---|---|
| Tracked KEV entries | 385 |
| Median lag (public → KEV listing) | 560 days |
| 0-day rate (exploited at or before disclosure) | 23% |
| Entries tied to known ransomware campaigns | 104 |
For perspective, the median across all 1670 tracked KEV entries is 268 days — Microsoft’s exploited vulnerabilities are flagged slower than the catalog average.
Other Recent Microsoft KEV Additions
The most recent Microsoft vulnerabilities CISA has confirmed as actively exploited, from our tracker:
| CVE | Product | Added to KEV | Lag (days) | Ransomware |
|---|---|---|---|---|
| CVE-2026-55040 | SharePoint | August 18, 2026 | 35 | No |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | August 11, 2026 | 0 | No |
| CVE-2026-50522 | SharePoint | July 22, 2026 | 8 | No |
| CVE-2026-58644 | SharePoint | July 16, 2026 | 2 | No |
| CVE-2026-56155 | Active Directory Federation Services | July 14, 2026 | 0 | No |
What This Means for Defenders
CISA has added CVE-2026-33824 to its KEV catalog, a vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions with a CVSS base score of 9.8. Federal agencies must patch this critical vulnerability by August 21, 2026, just three days after its KEV listing on August 18, 2026. All organizations leveraging Microsoft IKE for secure communications should also prioritize patching.
The vulnerability was public for 126 days before its KEV addition. Despite no confirmed ransomware use, the high CVSS score and CISA’s KEV inclusion signal a severe risk. Patching before the August 21 deadline is critical to prevent potential network compromise.
If immediate patching isn’t feasible, restrict access to IKE services, apply network segmentation, and monitor for unusual activity. Review firewall rules and intrusion detection/prevention systems to limit exposure and detect exploit attempts. Organizations should also hunt for any potential exploitation that may have occurred during the 126-day window.
Related Coverage
- Critical Microsoft SharePoint Flaw CVE-2026-50522 (CVSS 9.8) Added to CISA KEV (July 2026)
- Microsoft’s CVE-2026-68820 Was Exploited in 0 Days — Well Under Its 567-Day Median (August 2026)
How We Track This
This report was generated from our CISA KEV Lag Tracker, which syncs the official CISA KEV catalog daily and records the date each CVE is added. For every entry we retrieve the original NVD publication date and compute the lag in calendar days. No dates or figures on this page are estimated or taken from third-party sources — they come directly from CISA and NVD records.