CVE-2026-33824Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availableDouble free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 14.5 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
Federal remediation due Aug 21, 2026
56%
56% → 78%
2 GitHub repos
Added to the CISA catalog on Aug 18, 2026. Federal remediation due Aug 21, 2026. View catalog ↗
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
windows_10_1607 < 10.0.14393.9060windows_10_1809 < 10.0.17763.8644windows_10_21h2 < 10.0.19044.7184windows_10_22h2 < 10.0.19045.7184windows_11_23h2 < 10.0.22631.6936windows_11_24h2 < 10.0.26100.8246windows_11_25h2 < 10.0.26200.8246windows_11_26h1 < 10.0.28000.1836windows_server_2016 < 10.0.14393.9060windows_server_2019 < 10.0.17763.8644windows_server_2022 < 10.0.20348.5020windows_server_2022_23h2 < 10.0.25398.2274windows_server_2025 < 10.0.26100.32690Upgrade past the affected range:
windows_10_1607 10.0.14393.9060windows_10_1809 10.0.17763.8644windows_10_21h2 10.0.19044.7184windows_10_22h2 10.0.19045.7184windows_11_23h2 10.0.22631.6936windows_11_24h2 10.0.26100.8246windows_11_25h2 10.0.26200.8246windows_11_26h1 10.0.28000.1836windows_server_2016 10.0.14393.9060windows_server_2019 10.0.17763.8644windows_server_2022 10.0.20348.5020windows_server_2022_23h2 10.0.25398.2274windows_server_2025 10.0.26100.32690Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-32202Medium· 4.3Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2018-8174High· 7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…
CVE-2026-20805Medium· 5.5Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
CVE-2026-20832High· 7.8Windows Remote Procedure Call Interface Definition Language (IDL) Elevation of Privilege Vulnerability
CVE-2026-81963High· 7.8Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.