CVE-2026-33824Active Exploitation(microsoft / windows_10_1607)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 17 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-21. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-415

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 58 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 107 mentions across 35 observed days

What's happening

  • Active exploitation reported across 58 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 12 signals
  • Patch or workaround mentioned in 58 signals
  • Technical details provided in 87 signals
  • Disclosure: 21 classified signals
  • Peaked 14d ago at 17 mentions (2026-08-19); latest day: 1
  • 107 total mentions across 35 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2016windows_server_2019

Deep dive

Activity timeline107 mentions / 35d
0491317Mentions · 2026-04-14: 6Mentions · 2026-04-15: 9Mentions · 2026-04-16: 4Mentions · 2026-04-17: 3Mentions · 2026-04-18: 2Mentions · 2026-04-19: 3Mentions · 2026-04-20: 2Mentions · 2026-04-23: 4Mentions · 2026-04-24: 6Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-05-02: 1Mentions · 2026-05-05: 2Mentions · 2026-05-13: 1Mentions · 2026-05-14: 3Mentions · 2026-05-15: 1Mentions · 2026-06-15: 1Mentions · 2026-08-05: 1Mentions · 2026-08-18: 4Mentions · 2026-08-19: 17Mentions · 2026-08-20: 13Mentions · 2026-08-21: 5Mentions · 2026-08-22: 1Mentions · 2026-08-23: 2Mentions · 2026-08-24: 2Mentions · 2026-08-25: 2Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Mentions · 2026-08-28: 1Mentions · 2026-08-29: 2Mentions · 2026-08-30: 1Mentions · 2026-09-05: 1Mentions · 2026-09-09: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-05-05: 2PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-20: 4PoC Mentioned / Linked · 2026-08-21: 1Exploit Tool / Code · 2026-04-17: 1Exploit Tool / Code · 2026-06-15: 1Exploit Tool / Code · 2026-08-19: 1Exploit Tool / Code · 2026-08-20: 2Active Exploitation · 2026-04-15: 5Active Exploitation · 2026-04-16: 1Active Exploitation · 2026-04-17: 2Active Exploitation · 2026-04-18: 2Active Exploitation · 2026-04-19: 2Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-08-18: 3Active Exploitation · 2026-08-19: 17Active Exploitation · 2026-08-20: 10Active Exploitation · 2026-08-21: 3Active Exploitation · 2026-08-23: 2Active Exploitation · 2026-08-24: 2Active Exploitation · 2026-08-25: 2Active Exploitation · 2026-08-26: 1Active Exploitation · 2026-08-27: 1Active Exploitation · 2026-08-30: 1Active Exploitation · 2026-09-05: 1Active Exploitation · 2026-09-09: 1Patch / Workaround · 2026-04-14: 3Patch / Workaround · 2026-04-15: 2Patch / Workaround · 2026-04-16: 3Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-18: 1Patch / Workaround · 2026-04-19: 2Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-23: 2Patch / Workaround · 2026-04-24: 5Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-08-05: 1Patch / Workaround · 2026-08-19: 8Patch / Workaround · 2026-08-20: 10Patch / Workaround · 2026-08-21: 3Patch / Workaround · 2026-08-22: 1Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-08-24: 1Patch / Workaround · 2026-08-25: 2Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-29: 1Patch / Workaround · 2026-08-30: 1Patch / Workaround · 2026-09-09: 1Technical Details · 2026-04-14: 6Technical Details · 2026-04-15: 6Technical Details · 2026-04-16: 4Technical Details · 2026-04-17: 3Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-23: 4Technical Details · 2026-04-24: 6Technical Details · 2026-04-26: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-14: 2Technical Details · 2026-06-15: 1Technical Details · 2026-08-05: 1Technical Details · 2026-08-18: 3Technical Details · 2026-08-19: 16Technical Details · 2026-08-20: 8Technical Details · 2026-08-21: 5Technical Details · 2026-08-23: 2Technical Details · 2026-08-24: 2Technical Details · 2026-08-25: 2Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 1Technical Details · 2026-08-28: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-05: 1Technical Details · 2026-09-09: 104-1404-1704-2004-2605-0205-1408-0508-2008-2308-2608-2909-0910-02
Signal classification5 categories
Active Exploitation
4643.4%
Patch
2927.4%
Disclosure
2119.8%
General
76.6%
PoC
32.8%
Referenced assets87 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-146
Disclosure3Patch3
2026-04-159
Active Exploitation4Disclosure1General3Patch1
2026-04-164
Disclosure3Patch1
2026-04-173
Active Exploitation1Patch1PoC1
2026-04-182
Active Exploitation1Patch1
2026-04-193
Active Exploitation2Patch1
2026-04-202
Disclosure1Patch1
2026-04-234
Disclosure3Patch1
2026-04-246
Disclosure1General1Patch4
2026-04-261
Patch1
2026-04-271
Patch1
2026-04-291
Disclosure1
2026-05-021
General1
2026-05-052
Active Exploitation1Disclosure1
2026-05-131
Disclosure1
2026-05-143
Disclosure2Patch1
2026-05-151
General1
2026-06-151
PoC1
2026-08-051
Patch1
2026-08-184
Active Exploitation3Disclosure1
2026-08-1917
Active Exploitation17
2026-08-2013
Active Exploitation8Patch4PoC1
2026-08-215
Active Exploitation3Disclosure1General1
2026-08-221
Patch1
2026-08-232
Active Exploitation1Patch1
2026-08-242
Active Exploitation1Patch1
2026-08-252
Patch2
2026-08-261
Patch1
2026-08-271
Active Exploitation1
2026-08-281
Disclosure1
2026-08-292
Disclosure1Patch1
2026-08-301
Active Exploitation1
2026-09-051
Active Exploitation1
2026-09-091
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Four Critical Flaws Under Active Exploitation: • macOS CVE-2026-65400 • SharePoint CVE-2026-55040 • vCenter CVE-2026-59310 • Microsoft IKE CVE-2026-33824 Reported attacks include Monero mining, persistent access, and Babuk-derived ransomware. Read: https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html

    Post summary

    The tweet announces four CVEs currently under active exploitation, noting attacks such as Monero mining and ransomware, but offers no detailed technical or patch information.

    49933329452.8K
    2.4M followersView on X
  • TrendAI Zero Day Initiative@thezdi
    Disclosure

    CVE-2026-33824: Remote Code Execution in Windows IKEv2 - the folks from TrendAI Research break down this wormable bug that was patched last week. The show root cause & offer detection guidance. Read the details as https://www.zerodayinitiative.com/blog/2026/4/22/cve-2026-33824-remote-code-execution-in-windows-ikev2

    Post summary

    The post reports that CVE‑2026‑33824 is a remote‑code‑execution flaw in Windows IKEv2, notes it was patched recently, and offers detection guidance, but provides no PoC, exploit tool, or evidence of active exploitation.

    13731136217.6K
    88.7K followersView on X
  • yousukezan@yousukezan
    Disclosure

    VPNの入口に穴が開いた話 — CVE-2026-33824 で最初に見るのは役割ではなくポート|hashitoz https://zenn.dev/hashitoz/articles/2026-08-19-fleet-devlog-doraemon-portal-zenn #zenn

    Post summary

    The text refers to a new CVE affecting a VPN entry point, highlighting a port focus, but it does not provide actionable PoC, exploit, or mitigation details.

    08063425.5K
    16.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    🚨 Windows'ta kritik RCE açığı aktif olarak istismar ediliyor! CVE-2026-33824, Windows IKE Extension bileşenindeki bir "double-free" hatasından kaynaklanıyor. — Kimlik doğrulaması gerektirmiyor — Ağ üzerinden uzaktan kod çalıştırılabiliyor — IKEv2 etkin sistemleri etkiliyor — UDP 500 ve 4500 saldırı yüzeyinde CISA, CVE-2026-33824'ü Known Exploited Vulnerabilities (KEV) kataloğuna ekledi. Windows sistemlerinizi güncelleyin. IKE/IPsec kullanılmıyorsa UDP 500/4500 için inbound erişimi de engellemeyi düşünün.

    Post summary

    The post highlights that CVE‑2026‑33824 is actively exploited in the wild, detailing a double‑free RCE, while urging updates and network restrictions but offering no PoC or exploit code.

    15141212.9K
    2.4K followersView on X
  • Mitja Kolsek@mkolsek
    Active Exploitation

    CVE-2026-33824 is now being exploited in the wild. The only patches available for legacy Windows systems can be obtained from @0patch. https://0patch.com/blog/micropatches-released-for-windows-ike-service-extensions

    Post summary

    CVE-2026-33824 is reportedly being exploited in the wild, and patches for legacy Windows systems are available via 0patch.

    111036116.3K
    4.0K followersView on X
  • TrendAI Zero Day Initiative@thezdi
    Disclosure

    The April release is so large, it gets not one but TWO bugs of the month. Not surprisingly, they are the two wormable bugs in the release affecting TCP/IP and IKE. Enjoy CVE-2026-33824 and CVE-2026-33827. https://t.co/Euz0whc81M

    Post summary

    The tweet announces two wormable CVEs (2026-33824 & 33827) affecting TCP/IP and IKE, with no exploit or patch details provided.

    060221410.1K
    88.7K followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for Windows Internet Key Exchange Service Extensions RCE (CVE-2026-33824) https://0patch.com/blog/micropatches-released-for-windows-ike-service-extensions https://t.co/JsvrDjXnGR

    Post summary

    The tweet announces that Microsoft has released micropatches to fix a Remote Code Execution vulnerability (CVE‑2026‑33824) in Windows Internet Key Exchange Service Extensions.

    0301661.5K
    8.4K followersView on X
  • DarkFeed@ido_cohen2
    Active Exploitation

    ⚠️ New Actively-Exploited Vulnerability • CVE-2026-33824 impacts Microsoft IKE Service. • Double free flaw allows remote code execution. • Listed in CISA KEV, not linked to ransomware. Ensure compliance with CISA’s BOD 26-04. Full report: 🔗 https://darkfeed.io #CyberSecurity #CISA #Microsoft

    Post summary

    CVE‑2026‑33824 is a double‑free bug in Microsoft IKE Service that enables remote code execution and is known to be actively exploited, as indicated by its listing in CISA KEV; no patch or PoC is referenced in the posting.

    0201432.1K
    48.4K followersView on X
  • Autumn Good@autumn_good_35
    General

    今月気になるのはワーム化の可能性があるWindows TCP/IPのRCE(CVE-2026-33827)やWindows IKE拡張機能のRCE(CVE-2026-33824)、APT29が悪用しそうなRDPクライアントのRCE(CVE-2026-32157)ですね。 Zero Day Initiative — The April 2026 Security Update Review https://www.zerodayinitiative.com/blog/2026/4/14/the-april-2026-security-update-review

    Post summary

    The post lists three Windows RCE CVEs, noting their potential for worming and possible exploitation by APT29, but provides no PoC, exploit code, active usage data, or patch guidance.

    330541.9K
    6.9K followersView on X
  • Horizon Secured@horizon_secured
    Disclosure

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝗽𝗿𝗶𝗹 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 This month brings 2 Zero-Days and 2 additional 9.0+ vulnerabilities. 𝗠𝗮𝗶𝗻 𝗶𝘀𝘀𝘂𝗲𝘀 𝘁𝗼 𝘄𝗮𝘁𝗰𝗵: • CVE-2026-33825 – Microsoft Defender EoP (BlueHammer) • CVE-2026-32201 – SharePoint spoofing • CVE-2026-33824 – Windows IKE RCE • CVE-2026-26149 – Power Apps security bypass Full breakdown in this month’s Horizon Alert. #PatchTuesday #CyberSecurity #ZeroDay #Vulnerability #Microsoft

    Post summary

    The tweet announces four new CVEs—two zero‑days and two high‑severity vulnerabilities—listing affect Microsoft Defender, SharePoint, Windows IKE, and Power Apps, but provides no PoC, exploit details, or patch information.

    010911.2K
    2.5K followersView on X
  • Hackers Online Club (HOC)@HOCupdate
    Disclosure

    CISA Warns - AI powered Zero-Day Alert! Microsoft Internet Key Exchange (IKE) Extensions (`CVE-2026-33824`) — CVSS 9.8 Broadcom VMware vCenter (`CVE-2026-59310`) — CVSS 9.8 Apple macOS Screen Sharing (`CVE-2026-65400`) — CVSS 9.8 Microsoft SharePoint Server (`CVE-2026-55040`) — CVSS 9.1 https://hackersonlineclub.com/ai-powered-zero-day-windows-and-vmware/

    Post summary

    CISA has announced four new high‑severity zero‑day CVEs affecting Microsoft IKE, VMware vCenter, macOS Screen Sharing, and Microsoft SharePoint, highlighting their CVSS scores but providing no exploit or patch details.

    02021540
    27.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/18追加) #vulnerability 🛡CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / Microsoft Corporation (CNA) ・種別:二重解放 (CWE-415) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Microsoft Windows Internet Key Exchange (IKE) Service Extensions に存在する、二重解放の脆弱性です。 未認証の攻撃者がネットワーク経由で悪用することで、対象システム上でコードを実行できる可能性があります。 影響を受ける製品には、Windows 10、Windows 11、Windows Server 2019、Windows Server 2022、Windows Server 2025 などの複数バージョンが含まれます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月21日 ・BOD 26-04 対処期限(露出なし):2026年9月1日 ✅攻撃前提条件 ・影響を受ける Windows または Windows Server を使用している ・IKE Service Extensions が利用可能な状態である ・攻撃者が対象システムへネットワーク経由で到達できる ・攻撃者は認証情報を必要としない ・Microsoft が提供する修正済み更新プログラムが適用されていない ✅悪用時影響 ・未認証の攻撃者にリモートコードを実行される可能性がある ・対象システムを侵害される可能性がある ・機密性、完全性、可用性に高い影響が生じる可能性がある ・VPN/IKE 関連サービスを入口として追加侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Unit 42) ・概要:Unit 42 は、中国語話者とみられる攻撃者による AI 支援型の攻撃キャンペーンにおいて、CVE-2026-33824 を対象にした手動の悪用およびリバースシェル試行を確認したと報告 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-33824 ・https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/33xxx/CVE-2026-33824.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-33824 ・https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ ・https://jvndb.jvn.jp/ja/cwe/CWE-415.html 🛡CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability ✅概要 ・深刻度:緊急 9.1 (CVSS Base) / Microsoft Corporation (CNA) ・種別:弱い認証 (CWE-1390) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Microsoft Office SharePoint に存在する、弱い認証に起因するセキュリティ機能バイパスの脆弱性です。 未認証の攻撃者がネットワーク経由で悪用することで、SharePoint のセキュリティ機能を回避できる可能性があります。 影響を受ける製品には、Microsoft SharePoint Enterprise Server 2016、Microsoft SharePoint Server 2019、Microsoft SharePoint Server Subscription Edition が含まれます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月21日 ・BOD 26-04 対処期限(露出なし):2026年9月1日 ✅攻撃前提条件 ・Microsoft SharePoint Enterprise Server 2016、Microsoft SharePoint Server 2019、または Microsoft SharePoint Server Subscription Edition を使用している ・SharePoint Enterprise Server 2016 で 16.0.5561.1001 未満を使用している ・SharePoint Server 2019 で 16.0.10417.20175 未満を使用している ・SharePoint Server Subscription Edition で 16.0.19725.20434 未満を使用している ・攻撃者が対象 SharePoint Server へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・Microsoft が提供する修正済み更新プログラムが適用されていない ✅悪用時影響 ・SharePoint の認証機構またはセキュリティ機能を回避される可能性がある ・任意の SharePoint ユーザーまたは管理者として操作される可能性がある ・SharePoint 上の機密情報へ不正アクセスされる可能性がある ・他の SharePoint 脆弱性と組み合わせて、より深刻な侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開済み ・ITW:確認済み(BleepingComputer / Rapid7) ・概要:BleepingComputer は、Rapid7 の技術詳細と PoC 公開後に本脆弱性を悪用した攻撃が確認されたと報道 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-55040 ・https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55040 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/55xxx/CVE-2026-55040.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-55040 ・https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/ ・https://github.com/sfewer-r7/CVE-2026-55040 ・https://www.bleepingcomputer.com/news/microsoft/hackers-leverage-new-microsoft-sharepoint-exploit-in-attacks/ ・https://jvndb.jvn.jp/ja/cwe/CWE-1390.html 🛡CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / VMware (CNA) ・種別:パス・トラバーサル (CWE-22) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H VMware vCenter の Syslog server に存在するパス・トラバーサルの脆弱性です。 vCenter へネットワークアクセス可能な攻撃者が悪用することで、任意コード実行につながる可能性があります。 影響を受ける製品には vCenter、VMware Cloud Foundation、VMware vSphere Foundation、Telco Cloud Infrastructure、Telco Cloud Platform が含まれます。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月21日 ・BOD 26-04 対処期限(露出なし):2026年9月1日 ✅攻撃前提条件 ・VMware vCenter または関連する VMware Cloud Foundation / vSphere Foundation 環境を使用している ・vCenter 9.1.x.x で 9.1.0.0300 未満、9.0.x.x で 9.0.2.0100 未満、または 8.0 で 8.0 U3k 未満を使用している ・攻撃者が vCenter へネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・Broadcom / VMware が提供する修正済みバージョンへ更新されていない ✅悪用時影響 ・vCenter Syslog server のパス処理を悪用される可能性がある ・制限されたディレクトリ外のファイルへアクセスまたは書き込みされる可能性がある ・vCenter 上で任意コード実行につながる可能性がある ・仮想化管理基盤を侵害される可能性がある ・管理対象の仮想化環境やクラウド基盤へ追加侵害される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み(Quirso) ・概要:Quirso は、CVE-2026-59310 の能動的な悪用を確認し、47か国の 361 被害 IP に及ぶ観測結果や、疑わしい中国系 APT 関連の悪用について報告 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-59310 ・https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/59xxx/CVE-2026-59310.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310 ・https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff ・https://medium.com/@quirso_de/global-exploitation-of-cve-2026-59310-by-suspected-chinese-nexus-apt-related-cve-2026-59309-443a79e1466d ・https://jvndb.jvn.jp/ja/cwe/CWE-22.html 🛡CVE-2026-65400 Apple macOS Improper Authentication Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / CISA-ADP ・種別:不適切な認証 (CWE-287) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Apple macOS の Screen Sharing に存在する、不適切な認証の脆弱性です。 状態管理の不備により、ネットワーク上の攻撃者が有効な認証情報なしで Screen Sharing へ認証できる可能性があります。 本脆弱性は macOS Sonoma 14.8.9、macOS Sequoia 15.7.9、macOS Tahoe 26.6.1 で修正されています。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月21日 ・BOD 26-04 対処期限(露出なし):2026年9月1日 ✅攻撃前提条件 ・macOS Sonoma 14.8.9 未満、macOS Sequoia 15.7.9 未満、または macOS Tahoe 26.6.1 未満を使用している ・Screen Sharing が有効である ・攻撃者が対象 Mac の Screen Sharing サービスへネットワーク経由でアクセスできる ・特に TCP/5900 などの画面共有関連ポートがインターネットまたは攻撃者到達可能なネットワークに露出している ・Apple が提供する修正済みバージョンへ更新されていない ✅悪用時影響 ・有効な認証情報なしで Screen Sharing に認証される可能性がある ・対象 Mac をリモート操作される可能性がある ・root 権限相当の不正操作につながる可能性がある ・暗号資産マイナーなどの不正プログラムを配置される可能性がある ・対象端末上の機密情報や認証情報を窃取される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(NCSC-NL) ・概要:NCSC-NL は、インターネットに Screen Sharing を露出した macOS 環境に対して CVE-2026-65400 が悪用され、Monero マイナーの展開に使われていることを公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-65400 ・https://support.apple.com/en-us/148170 ・https://support.apple.com/en-us/148171 ・https://support.apple.com/en-us/148172 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/65xxx/CVE-2026-65400.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-65400 ・https://advisories.ncsc.nl/2026/ncsc-2026-0280.html ・https://jvndb.jvn.jp/ja/cwe/CWE-287.html CISA Alert ・https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA added four known‑exploited vulnerabilities (CVE‑2026‑33824, CVE‑2026‑55040, CVE‑2026‑59310, CVE‑2026‑65400) to its KEV catalog, confirming that these high‑severity flaws are being actively exploited in the wild and that exploit code and patches are publicly available.

    000326.0K
    45.5K followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🚨 CISA has added CVE-2026-33824 to its KEV catalog. The critical Windows IKE flaw can enable unauthenticated remote code execution and puts VPN infrastructure at risk. Organizations should patch affected systems immediately. #CyberSecurity #CISA Read more: https://thecyberedition.com/cisa-flags-critical-windows-ike-flaw-cve-2026-33824-for-urgent-exploitation-patch/

    Post summary

    CISA has added CVE‑2026‑33824 to its KEV catalog, noting it is a critical Windows IKE flaw that enables unauthenticated remote code execution and jeopardizes VPN infrastructure, and urges immediate patching.

    00040188
    767 followersView on X
  • National CERT/CC@CERT_UG
    Patch

    🚨 August 20, 2026 Patches: CISA orders patching of 3 critical flaws by August 21. - Microsoft IKE (CVE-2026-33824, CVSS 9.8) - Adobe Commerce (CVE-2026-71362 CVSS 9.8) - SharePoint (CVE-2026-55040, CVSS 9.1) https://cert.ug | #CyberSafeUG #CERTUGCC https://t.co/86SXyzwJO2

    Post summary

    CISA mandates urgent patching of three high‑severity CVEs by August 21, emphasizing the importance of timely updates.

    01030123
    1.5K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-33824 PT ID: PT-2026-32883 Vendor: Microsoft Product: Windows 10 Version 1607 Description: Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. Link: https://github.com/EpSiLoNPoInTOrI/IKEV2-POC #dbugs_vuln

    Post summary

    The tweet announces a discovered PoC/exploit for CVE‑2026‑33824, links to GitHub code, and details a double‑free vulnerability in Windows IKE Extension that permits remote code execution. No indications of active exploitation or available patches are provided.

    00013379
    3.0K followersView on X
  • YourDailyCVE@YourDailyCVE
    Active Exploitation

    🚨 CVE-2026-33824 — Windows IKE Service Extensions, pre-auth double-free RCE Who should care: Windows 10/11/Server with IKEv2 enabled and UDP 500 or 4500 reachable from untrusted networks — VPN gateways first, also RRAS / Always On VPN hosts. Impact: IKE is the handshake that sets up IPsec VPN tunnels. This bug sits in that pre-auth path, so no VPN account and no user click. A crafted packet can run code as SYSTEM on an internet-facing gateway. Status: exploited. Microsoft patched it in April 2026. CISA KEV Aug 18 (federal deadline was Aug 21). Unit 42 reported reverse-shell attempts against three IKE VPN endpoints. Microsoft’s advisory still treats exploitation as less likely than CISA does. Fix today: April 2026 Windows updates or later. Can't patch: disable IKEv2 if unused; otherwise restrict UDP 500/4500 to known peers. Hunt odd IKE negotiation and unexpected processes on the gateway. Source: MSRC CVE-2026-33824 / CISA KEV / Unit 42 #Windows

    Post summary

    CVE‑2026‑33824 is a pre‑authentication double‑free RCE affecting Windows IKE v2, actively exploited in the wild as confirmed by Unit 42, and has already been addressed by a Microsoft patch released in April 2026.

    10020225
    34 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    🚨Windows IKEにおけるRCE脆弱性が悪用される(CVE-2026-33824) 〜サイバーアラート8月20日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47275/

    Post summary

    CVE-2026-33824 is a Windows IKE Remote Code Execution vulnerability that is being actively exploited according to a threat alert, though no exploit code or patch details are disclosed.

    00021247
    1.3K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。 - CVE-2026-33824 (Windows) - CVE-2026-55040 (Sharepoint) - CVE-2026-59310 (vCenter) - CVE-2026-65400 (macOS) 対処期限は3日後の8/21。 https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog ランサムウェア​による悪用は不知。 差分:https://kev.kokumoto.com/#/dateAdded:2026-08-18

    Post summary

    The notice reports that CISA has added four CVEs to its known‑exploit catalog, setting a remediation deadline but providing no PoC, exploit details, or patch information.

    000301.0K
    7.8K followersView on X
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    General

    ウィンドウズ10 1607脆弱性の要点と対処法をチェック 【脆弱性情報】 CVE-2026-33824 microsoftのwindows 10 1607の脆弱性について https://www.cybernote.click/2026/04/19/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-33824-microsoft%e3%81%aewindows-10-1607%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/?utm_source=rss&utm_medium=rss&utm_campaign=%25e3%2580%2590%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e6%2583%2585%25e5%25a0%25b1%25e3%2580%2591-cve-2026-33824-microsoft%25e3%2581%25aewindows-10-1607%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The post links to a blog entry about CVE‑2026‑33824 affecting Windows 10 1607 but offers no explicit technical details, PoC, patch, or exploitation information.

    0003075
    210 followersView on X
  • Vicarius@vicariusltd
    Patch

    Take care of patches just like our planet! 🌎 _____ CVE of the Week CVE-2026-33824: Critical RCE in Windows Internet Key Exchange (IKE) Service This double-free vulnerability allows an unauthenticated, remote attacker to execute arbitrary code with SYSTEM privileges by sending specially crafted packets to a target server. Exploiting this vulnerability could result in: - Remote code execution at the highest privilege level without needing user interaction. - Attackers can trigger this memory corruption over a network on any system with IKEv2 enabled. Recommended actions: 1. Apply the April 2026 Microsoft Patch Tuesday cumulative security updates to all affected Windows 10, 11, and Server (2012–2025) systems. 2. If patching has to be delayed, restrict inbound traffic on UDP ports 500 and 4500. Use the following mitigation script from the Vicarius Research Team to apply the workaround: https://www.vicarius.io/vsociety/posts/cve-2026-33824-mitigation-script-windows-ike-service-extensions-rce The workaround eliminates the attack surface by: 1. Disabling the IKEEXT ("IKE and AuthIP IPsec Keying Modules") service. 2. Creating Windows Firewall rules to block inbound UDP traffic on ports 500 and 4500. 3. Stopping the service immediately if it is currently running. When in doubt, script it out! 🍻

    Post summary

    The text announces CVE-2026-33824, details its RCE impact, and provides both patch and a mitigation script to protect against exploitation.

    00030146
    2.0K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more