CISA Cybersecurity Directives & Advisories Brief
Headline
CISA adds Microsoft IKE double-free remote code execution flaw to Known Exploited Vulnerabilities catalog with August 21 federal deadline
Executive Summary
CISA added CVE-2026-33824 to its Known Exploited Vulnerabilities catalog on August 18, 2026. The vulnerability is a double-free flaw in Microsoft Internet Key Exchange Service Extensions that enables remote code execution. Federal agencies must apply vendor mitigations or discontinue use of the affected product by August 21, 2026.
Bottom Line
The KEV catalog addition places a binding remediation obligation on all civilian federal executive branch agencies: apply Microsoft's mitigations for CVE-2026-33824 or remove the product from service by August 21, 2026. The forensics triage requirement under BOD 26-04 means agencies must also assess and document each asset's internet exposure, not only apply the patch. For non-federal operators, KEV catalog placement signals confirmed active exploitation and carries the same technical urgency, even absent a binding federal deadline.
Key Regulatory Signals
- Three-Day Federal Remediation Window: Federal agencies face a remediation deadline of August 21, 2026, three days from the catalog addition date. Agencies must apply Microsoft-issued mitigations or, where mitigations are unavailable, discontinue use of the affected IKE Service Extensions product entirely.
- Forensics Triage Requirements Apply: CISA's Binding Operational Directive 26-04 activates forensics triage requirements alongside the patching obligation. Agencies must evaluate each affected asset's internet exposure and document adherence to the directive's patching guidelines, not merely apply the patch.
- Cloud Service Operators Face Separate Guidance Track: BOD 26-04 carries distinct guidance for cloud-hosted deployments of the affected service. Agencies and operators running IKE Service Extensions in cloud environments must follow that cloud-specific track rather than the standard on-premises remediation path.
- Remote Code Execution Severity Drives Catalog Priority: The double-free vulnerability class in a network authentication service carries remote code execution potential without requiring local access. KEV catalog placement confirms active exploitation in the wild, which is CISA's threshold for mandatory federal action under BOD 22-02.
Regulatory Delta
- Prior KEV catalog entries have covered IKE and VPN-adjacent vulnerabilities, but a double-free flaw in Microsoft's IKE Service Extensions that permits unauthenticated remote code execution represents a higher severity class than those earlier entries.
- The three-day remediation window is among the shortest deadlines issued under BOD 26-04, reflecting CISA's risk-based tiering for actively exploited remote code execution vulnerabilities in network authentication services.
- No parallel emergency directive from NSA or CISA's Emergency Directive channel accompanies this KEV addition. BOD 26-04's mandatory patching framework nonetheless carries equivalent binding force for civilian federal executive branch agencies.
Materiality Classification
HIGH — CISA's KEV catalog addition under BOD 26-04 imposes a binding three-day remediation deadline on all civilian federal executive branch agencies and confirms active exploitation of a remote code execution vulnerability in a widely deployed network authentication service, requiring immediate asset assessment and patch action across the federal civilian enterprise.
Time Horizon
implementation — 2026-08-21
Intelligence Outlook
Monitor CISA's Known Exploited Vulnerabilities catalog and Microsoft Security Response Center for updated mitigation guidance or patch availability for this vulnerability.