Three days to patch a four-month-old fix
An unauthenticated RCE in the Windows IKE service is under attack. The patch shipped in April; federal agencies now have seventy-two hours.
2 minEnterprise CyberSec
CVE-2026-33824 is a double-free in the Windows Internet Key Exchange service extensions. An unauthenticated attacker can execute code by sending crafted packets to UDP port 500 or 4500. Every supported release of Windows 10, Windows 11 and Windows Server is affected.
Microsoft shipped the fix in the April 2026 Patch Tuesday. CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 18 August, confirming active exploitation, and set a remediation deadline of three days for federal civilian agencies under Binding Operational Directive 26-04.
Why the ports matter more than the CVE
UDP 500 and 4500 are IKE and IPsec NAT traversal — the ports a VPN concentrator listens on by design. This is not an internal service someone forgot to firewall; it is the service whose whole job is accepting unauthenticated packets from the internet before a tunnel exists.
For anyone who cannot patch immediately, the advice is to block inbound UDP on both ports or restrict them to known peer addresses. On a device terminating remote-access VPN for a distributed workforce, neither is straightforward, which is the practical reason a four-month-old patch is still unapplied in enough places to matter.
A three-day deadline is unusually short even by KEV standards. It is worth reading as a statement about what CISA is seeing rather than about the CVSS score.
Retold from BleepingComputer. This is a summary in our own words; follow the link for the original reporting.