// Alert

Microsoft 365 threat report

CISA added CVE-2026-33824, a critical double-free vulnerability in Microsoft Internet Key Exchange Service Extensions, to its Known Exploited Vulnerabilities catalog on August 18, 2026, after confirming active exploitation. The flaw enables remote code execution on Windows systems with IKE enabled. A mandatory remediation deadline of August 21, 2026, was set for federal agencies under BOD 26-04.

// Get alerts for Microsoft 365