// Microsoft 365CRITICAL
CISA added CVE-2026-33824, a critical double-free vulnerability in Microsoft Internet Key Exchange Service Extensions, to its Known Exploited Vulnerabilities catalog on August 18, 2026, after confirming active exploitation. The flaw enables remote code execution on Windows systems with IKE enabled. A mandatory remediation deadline of August 21, 2026, was set for federal agencies under BOD 26-04.
- U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMwar(opens in a new tab)
- CISA Urges Immediate Patching of Exploited Microsoft, VMware, Ap(opens in a new tab)
- CISA Adds Microsoft Internet Key Exchange RCE Vulnerability Expl(opens in a new tab)
- CISA KEV Adds 4 Critical CVEs, 3 at CVSS 9.8(opens in a new tab)
// Get alerts for Microsoft 365