CVE-2026-33827Disclosure(microsoft / windows_10_1607)

HIGHCVSS 8.1 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.

6.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 7 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 24 mentions across 11 observed days

What's happening

  • Active exploitation reported across 7 signals
  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 18 signals
  • Disclosure: 12 classified signals
  • General: 4 classified signals
  • Peaked 7d ago at 6 mentions (2026-04-19); latest day: 1
  • 24 total mentions across 11 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline24 mentions / 11d
02356Mentions · 2026-04-14: 2Mentions · 2026-04-15: 5Mentions · 2026-04-17: 1Mentions · 2026-04-19: 6Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Mentions · 2026-04-27: 1Mentions · 2026-05-13: 2Mentions · 2026-05-14: 3Mentions · 2026-06-14: 1Mentions · 2026-09-04: 1Exploit Tool / Code · 2026-04-23: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-19: 4Active Exploitation · 2026-04-23: 1Active Exploitation · 2026-04-27: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-19: 2Patch / Workaround · 2026-04-23: 1Patch / Workaround · 2026-04-27: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 2Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 4Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 6Technical Details · 2026-04-23: 1Technical Details · 2026-04-27: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 2Technical Details · 2026-09-04: 104-1404-1504-1704-1904-2204-2304-2705-1305-1406-1409-04
Signal classification4 categories
Disclosure
1250.0%
Active Exploitation
520.8%
General
416.7%
Patch
312.5%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure1General1
2026-04-155
Disclosure4General1
2026-04-171
Active Exploitation1
2026-04-196
Active Exploitation3Disclosure1Patch2
2026-04-221
General1
2026-04-231
Active Exploitation1
2026-04-271
Patch1
2026-05-132
Disclosure2
2026-05-143
Disclosure3
2026-06-141
General1
2026-09-041
Disclosure1
Full discourse20 posts
  • TrendAI Zero Day Initiative@thezdi
    General

    The April release is so large, it gets not one but TWO bugs of the month. Not surprisingly, they are the two wormable bugs in the release affecting TCP/IP and IKE. Enjoy CVE-2026-33824 and CVE-2026-33827. https://t.co/Euz0whc81M

    Post summary

    The tweet announces two wormable bugs, CVE-2026-33824 and CVE-2026-33827, without providing additional technical or exploit details.

    060221410.1K
    88.7K followersView on X
  • Autumn Good@autumn_good_35
    General

    今月気になるのはワーム化の可能性があるWindows TCP/IPのRCE(CVE-2026-33827)やWindows IKE拡張機能のRCE(CVE-2026-33824)、APT29が悪用しそうなRDPクライアントのRCE(CVE-2026-32157)ですね。 Zero Day Initiative — The April 2026 Security Update Review https://www.zerodayinitiative.com/blog/2026/4/14/the-april-2026-security-update-review

    Post summary

    The post lists three recent CVEs (CVE‑2026‑33827, CVE‑2026‑33824, CVE‑2026‑32157) and notes they involve RCE and potential worm activity, without providing PoC, exploit code, patch details, or evidence of active exploitation.

    330541.9K
    6.9K followersView on X
  • Lukasz Olejnik@lukOlejnik
    Disclosure

    Microsoft used AI to find a critical bug in Windows. It was sufficient to send a network packet. Sometimes. The actual scarier bug is two rows down in the same table: IKEv2 double-free, two UDP packets. https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/?v=1#cve-2026-33827-remote-unauthenticated-uaf-in-tcpip-sys-via-ssrr https://t.co/aPzEtdwK8Y

    Post summary

    Microsoft’s AI‑driven analysis surfaced a remote unauthenticated use‑after‑free flaw in Windows TCP/IP involving two UDP packets, but no exploitation evidence, PoC, or patch information was provided.

    310231.2K
    31.0K followersView on X
  • Helios Mier@hmier
    Disclosure

    CVE-2026-33827 👀 Windows TCP/IP allows an unauthorized attacker to execute code over a network.

    Post summary

    A newly disclosed Windows TCP/IP flaw permits remote code execution by an unauthorized attacker.

    01020108
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2023-33308 2 - CVE-2022-42475 3 - CVE-2026-32201 4 - CVE-2026-33827 5 - CVE-2024-3721 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely enumerates trending CVEs with hashtags, offering no additional technical or operational details.

    00020264
    1.7K followersView on X
  • UniquePov@TangoZuloVictor
    General

    for the identification and analysis stages. It generated some nice posts for real recent CVEs (CVE-2026-33827, CVE-2026-26179, 2026-24289...) in the Windows kernel and TCPIP.sys. But then I tried to identify CVE-2026-26179 and CVE-2026-26169. Reading the reports carefully -->

    Post summary

    The message references several recent CVEs but provides no further technical details, PoC, exploit code, patch, or evidence of active exploitation.

    1000036
    20 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    Microsoft unveiled MDASH, an AI system with 100+ agents that found and proved 16 Windows flaws fixed in Patch Tuesday, including CVE-2026-33824 and CVE-2026-33827. #Microsoft #MDASH #Windows https://ift.tt/RjZY3hE

    Post summary

    Microsoft’s MDASH AI system uncovered 16 Windows vulnerabilities, including CVE-2026-33824 and CVE-2026-33827, which were all addressed in the recent Patch Tuesday release, illustrating the tool’s effective flaw‑finding capability.

    00001125
    4.3K followersView on X
  • Inferlume@inferlume_hq
    Active Exploitation

    April Patch Tuesday: 165 CVEs. One 0-day already being used: CVE-2026-32201 (SharePoint, CVSS 6.5 — the score is irrelevant, it's in active exploitation). CISA KEV. Federal deadline April 27. Also: CVE-2026-33827 (wormable TCP/IP RCE) + CVE-2026-33824 (IKE RCE, CVSS 9.8). 🔧 3/5

    Post summary

    The post highlights that CVE‑2026‑32201, a SharePoint 0‑day, is already being exploited, and lists additional CVEs with RCE weaknesses, underscoring active exploitation in the wild.

    1000088
    1 followersView on X
  • abhishek gautam@Abhs_tweets
    Active Exploitation

    164 CVEs in one Patch Tuesday is a wake-up call. Unauthenticated RCE + active exploitation + CISA deadline = this cannot wait for your monthly maintenance window. What is your patching priority this week — CVE-2026-33827, the Hyper-V escapes, or the ActiveMQ CISA deadline? Drop your environment and plan below 7/7 #DevSecOps #Cybersecurity #PatchTuesday #AppSec

    Post summary

    The message urges immediate patching of CVE‑2026‑33827 and related critical vulnerabilities because they are actively exploited and subject to a CISA deadline.

    1000075
    31 followersView on X
  • abhishek gautam@Abhs_tweets
    Active Exploitation

    Priority 2: Actively exploited zero-days (deploy immediately) One CVE confirmed exploited in the wild before the patch dropped — targets Windows authentication token handling. Two Hyper-V RCEs allow guest VM escape to hypervisor host. If you run Hyper-V in production, these move to the top of your queue alongside CVE-2026-33827. 3/7

    Post summary

    The post announces that one CVE is being actively exploited in the wild and that two Hyper‑V RCEs allow host escape, urging immediate action for those using Hyper‑V.

    1000051
    31 followersView on X
  • abhishek gautam@Abhs_tweets
    Patch

    Priority 1: Patch within 24-48 hours CVE-2026-33827 — Windows TCP/IP RCE (CVSS 8.1) Unauthenticated. No user interaction needed. Potentially wormable on IPv6/IPSec systems. Every internet-facing Windows server is exposed until this is patched. Domain controllers first — compromise here = full network compromise. 2/7

    Post summary

    The advisory highlights a Windows TCP/IP RCE (CVE‑2026‑33827) and urges immediate patching within 24‑48 hours without presenting evidence of active exploitation.

    1000065
    31 followersView on X
  • Patel Mahendra@Mahendrak29
    Disclosure

    https://whatsapp.com/channel/0029VbAre6eKQuJNLsryuQ0u/112 🔴 Zero-Day CVE-2026-32201 – SharePoint Spoofing CVE-2026-33825 – Publicly Disclosed 🔴 Critical: CVE-2026-33827 – Windows RCE CVE-2026-33826 – Active Directory RCE CVE-2026-32157 – RDP Client RCE CVE-2026-32190 – Microsoft Office RCE #cyber

    Post summary

    The message delivers a brief disclosure of several newly announced CVEs, indicating categories like RCE or spoofing, but provides no PoC, exploitation tools, active usage claims, or patch information.

    00010239
    1 followersView on X
  • UniquePov@TangoZuloVictor
    Disclosure

    New writeup of CVE-2026-33827 a windows kernel RCE caused by a use after free in the IPv4 routing is available in PatchBook! https://cvepatchbook.com Patchbook is a an open source community driven technical report library for closed source 1-Day vulnerabilities

    Post summary

    A new writeup of CVE-2026-33827, a Windows kernel remote‑code‑execution vulnerability caused by a use‑after‑free in IPv4 routing, has been published on PatchBook, providing technical details about the flaw.

    0000073
    24 followersView on X
  • Saudi ICT Shopper News | صحيفة سعودي شوبر@ssict
    Disclosure

    أبرز المميزات: ✅ اكتشاف ⁦21⁩ من ⁦21⁩ خطأ مدرج في ⁦StorageDrive⁩ دون إيجابيات كاذبة ✅ تحقيق ⁦100⁩٪ استرجاع على حالات ⁦tcpip.sys MSRC⁩ على مدى خمس سنوات ✅ ⁦CVE-2026-33827⁩: حالة سباق في مسار استقبال ⁦IPv4⁩ ✅ ⁦CVE-2026-33824⁩: تحرير مزدوج في معالجة ⁦IKEv2 SA_INIT⁩ ✅ دقة ⁦88.45⁩٪ على ⁦1⁩,⁦507⁩ مهام ثغرات واقعية من ⁦CyberGym⁩ Key Highlights: 🔹 Found 21 of 21 injected bugs in StorageDrive with zero false positives 🔹 Achieved 100% recall on tcpip.sys MSRC cases over five years 🔹 CVE-2026-33827: Race-condition UAF in IPv4 receive path 🔹 CVE-2026-33824: Double-free in IKEv2 SA_INIT handling 🔹 88.45% accuracy on CyberGym's 1,507 real-world vulnerability tasks

    Post summary

    The announcement provides technical details on two newly disclosed CVEs, highlighting identified bugs and accuracy metrics, with no indication of exploits or patches.

    00000116
    21.8K followersView on X
  • Proficio@proficioinc
    Disclosure

    Microsoft's MDASH AI System Finds 16 Windows Flaws (CVE-2026-33824 and CVE-2026-33827) Fixed in Patch Tuesday via @TheHackersNews #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://thehackernews.com/2026/05/microsofts-mdash-ai-system-finds-16.html

    Post summary

    MDASH AI identified 16 new Windows vulnerabilities, including CVE‑2026‑33824 and CVE‑2026‑33827, which Microsoft has addressed in the latest Patch Tuesday. No PoC or active exploitation is reported.

    00000113
    1.0K followersView on X
  • Data Value Consulting@DVC_analytics
    Disclosure

    Microsoft's MDASH orchestrated 100+ AI agents against Windows itself, uncovered 16 vulns shipped in this Patch Tuesday — critical RCEs in tcpip.sys (CVE-2026-33827) and IKEv2 (CVE-2026-33824). AI red team turned inward. https://msrc.microsoft.com/blog @Microsoft — Nexus https://t.co/MBwwe31Ntm

    Post summary

    Microsoft’s MDASH AI red team identified 16 critical RCEs shipped in this Patch Tuesday, including CVE‑2026‑33827 and CVE‑2026‑33824, with patches available but no exploit or PoC disclosed.

    0000054
    7 followersView on X
  • Sec4good@sec4good
    Patch

    Microsoft vydal dubnový Patch Tuesday Bylo opraveno 167 zranitelností, z toho 2 zero day a 8 kritických. Chyby nejčastěji umožňují: ➖eskalaci oprávnění ➖únik dat ➖vzdálené spuštění kódu Jaké zajímavé zranitelnosti byly nalezeny? ⚠️ CVE-2026-32201 v Microsoft SharePoint Server - aktivně zneužívaná, umožňuje získat přístup k datům a jejich úpravu ⚠️ CVE-2026-33825 v Microsoft Defender - též známá jako RedSun - umožňuje získání práv lokálního admina ⚠️ CVE-2026-33827 - chyba v TCP/IP stacku umožňující RCE přes síť Další opravy se týkají i Microsoft Word a Excel, kde chyby umožňovaly vzdálené spuštění kódu např. přes otevření souboru. Do jakého týmu patříte? Aktualizujete hned nebo to odkládáte? 👨‍💻

    Post summary

    Microsoft announced its April Patch Tuesday, fixing 167 vulnerabilities—including two zero-days—and highlighted that CVE-2026-32201 is actively exploited, urging users to apply the update.

    0000065
    20 followersView on X
  • Md. Najeeb Hussain@mnh_18
    Active Exploitation

    🪟 Microsoft April 2026 Patch Tuesday: 167 security flaws fixed — including 2 ZERO-DAYS! 🛡️ This is the SECOND-LARGEST Patch Tuesday in Microsoft's history! Critical fixes you MUST apply: 🔴 CVE-2026-32201 — SharePoint Server ZERO-DAY actively exploited in the wild! 😱 🔴 CVE-2026-33825 — Microsoft Defender privilege escalation (public exploit available!) 🔴 CVE-2026-33824 — Windows IKE: remote code execution via network! Critical! 🔴 CVE-2026-33827 — Windows TCP/IP stack race condition RCE! 🔴 CVE-2026-27906 — Windows Hello security bypass! Also: Secure Boot certificates expiring June 26, 2026 — Microsoft pushing updates NOW! Indian enterprise IT teams 🇮🇳 — patch your SharePoint servers IMMEDIATELY! ⚡ #Microsoft #PatchTuesday #Security #SharePoint #ZeroDay #WindowsSecurity

    Post summary

    Microsoft’s April 2026 Patch Tuesday included several zero-days, one of which is actively exploited in the wild and another with a publicly available exploit, and vendors urge immediate application of critical patches.

    00000109
    179 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-33827: Windows TCP/IP Race Condition - What It Means for Your Business and How to Respond https://hubs.li/Q04cDYQH0

    Post summary

    The headline announces CVE‑2026‑33827 as a Windows TCP/IP race condition and promises discussion of its business impact and response measures.

    0000050
    29 followersView on X
  • abhishek gautam@Abhs_tweets
    Patch

    Microsoft April 2026 Patch Tuesday fixes 164 CVEs including Windows TCP/IP CVE-2026-33827 unauthenticated RCE CVSS 8.1 and one actively exploited zero-day. Microsoft April 2026 Patch Tuesday: 164 CVEs, Windows RCE Zero-Day #Cybersecurity #DeveloperTools https://www.abhs.in/blog/microsoft-patch-tuesday-april-2026-164-cves-windows-rce-zero-day

    Post summary

    The entry announces Microsoft’s April 2026 Patch Tuesday, noting 164 CVEs fixed—including a high‑severity RCE—and mentions an actively exploited zero‑day, indicating that the primary focus is the patch release.

    00000147
    31 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more