ProductsIntelligencePricingMethodologyContact
Cresthaven AnalyticsIntelligence Brief

CISA Cybersecurity Directives & Advisories Brief

August 20, 2026·Cybersecurity and Infrastructure Security Agency (CISA)·US

CISA adds Microsoft IKE double-free remote code execution flaw to Known Exploited Vulnerabilities catalog with August 21 federal deadline

CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog on August 18, 2026. The vulnerability is a double-free flaw in Microsoft Internet Key Exchange Service Extensions that enables remote code execution. Federal agencies must apply vendor mitigations or discontinue use of the affected product by August 21, 2026.

The KEV catalog addition places a binding remediation obligation on all civilian federal executive branch agencies: apply Microsoft's mitigations for CVE-2026-33824 or remove the product from service by August 21, 2026. The forensics triage requirement under BOD 26-04 means agencies must also assess and document each asset's internet exposure, not only apply the patch. For non-federal operators, KEV catalog placement signals confirmed active exploitation and carries the same technical urgency, even absent a binding federal deadline.

  • Three-Day Federal Remediation Window: Federal agencies face a remediation deadline of August 21, 2026, three days from the catalog addition date. Agencies must apply Microsoft-issued mitigations or, where mitigations are unavailable, discontinue use of the affected IKE Service Extensions product entirely.
  • Forensics Triage Requirements Apply: CISA's Binding Operational Directive 26-04 activates forensics triage requirements alongside the patching obligation. Agencies must evaluate each affected asset's internet exposure and document adherence to the directive's patching guidelines, not merely apply the patch.
  • Cloud Service Operators Face Separate Guidance Track: BOD 26-04 carries distinct guidance for cloud-hosted deployments of the affected service. Agencies and operators running IKE Service Extensions in cloud environments must follow that cloud-specific track rather than the standard on-premises remediation path.
  • Remote Code Execution Severity Drives Catalog Priority: The double-free vulnerability class in a network authentication service carries remote code execution potential without requiring local access. KEV catalog placement confirms active exploitation in the wild, which is CISA's threshold for mandatory federal action under BOD 22-02.

- Prior KEV catalog entries have covered IKE and VPN-adjacent vulnerabilities, but a double-free flaw in Microsoft's IKE Service Extensions that permits unauthenticated remote code execution represents a higher severity class than those earlier entries.

- The three-day remediation window is among the shortest deadlines issued under BOD 26-04, reflecting CISA's risk-based tiering for actively exploited remote code execution vulnerabilities in network authentication services.

- No parallel emergency directive from NSA or CISA's Emergency Directive channel accompanies this KEV addition. BOD 26-04's mandatory patching framework nonetheless carries equivalent binding force for civilian federal executive branch agencies.

HIGH — CISA's KEV catalog addition under BOD 26-04 imposes a binding three-day remediation deadline on all civilian federal executive branch agencies and confirms active exploitation of a remote code execution vulnerability in a widely deployed network authentication service, requiring immediate asset assessment and patch action across the federal civilian enterprise.

implementation — 2026-08-21

Monitor CISA's Known Exploited Vulnerabilities catalog and Microsoft Security Response Center for updated mitigation guidance or patch availability for this vulnerability.

CISA Known Exploited Vulnerabilities Catalog (CVE-2026-33824); CISA Binding Operational Directive 26-04; CISA Binding Operational Directive 22-02; NVD entry https://nvd.nist.gov/vuln/detail/CVE-2026-33824

nvd.nist.gov — Source ↗

This is a sample intelligence brief from Cresthaven Analytics. Live subscribers receive briefs like this on a daily or weekly cadence depending on tier.