An unauthenticated RCE in Windows IKE is now exploited over UDP 500 and 4500
CISA added CVE-2026-33824, a remote code execution flaw in Windows IKE, to its Known Exploited Vulnerabilities catalog on August 18, 2026 — four months after Microsoft shipped the fix. Network teams must patch exposed IPsec gateways or block inbound UDP 500 and 4500 now.