The U.S. Cybersecurity and Infrastructure Security Agency has warned that attackers are exploiting a critical remote code execution vulnerability in Microsoft’s Windows Internet Key Exchange Service Extensions component, according to BleepingComputer. The flaw is tracked as CVE-2026-33824 and affects supported Windows 10, Windows 11, and Windows Server releases, BleepingComputer reports. Microsoft addressed the vulnerability during April 2026 Patch Tuesday, describing it in its advisory as a double-free issue in Windows IKE Extension that could let an unauthorized attacker execute code over a network. The vulnerable component, also known as MS-IKEE, extends the Internet Key Exchange protocol with capabilities including authentication using cryptographically generated addresses, denial-of-service protection, and interoperability with peers that do not support Internet Protocol Security. In practical terms, the issue sits in a Windows networking component used around IKE, a protocol associated with establishing secure communications. BleepingComputer reports that an unauthenticated attacker could target an unpatched Windows machine with IKE version 2 enabled by sending specially crafted packets over UDP ports 500 or 4500. Microsoft’s mitigation guidance for organizations that cannot immediately install the update is to block inbound traffic on those ports for systems that do not use IKE, or to restrict inbound traffic to known peer addresses where IKE is required. CISA has added CVE-2026-33824 to its catalog of actively exploited vulnerabilities and ordered U.S. Federal Civilian Executive Branch agencies to secure affected devices within three days, according to BleepingComputer. The agency also urged all network defenders to prioritize patching, even though the federal directive applies only to civilian executive branch agencies. One important gap remains: the public details of the attacks are still thin. BleepingComputer says Microsoft had not yet updated its advisory to mark the vulnerability as exploited at the time of the report, and that CISA and Microsoft had not responded to requests for more information about attacks targeting CVE-2026-33824. The report lands amid a broader pattern of Microsoft vulnerabilities being added to CISA’s known-exploited catalog. BleepingComputer notes that since November 2021, CISA has tagged 385 actively exploited vulnerabilities in Microsoft products, including 112 that ransomware groups also exploited. That context does not establish ransomware use for CVE-2026-33824, but it explains why CISA’s active-exploitation designation tends to move patching priority quickly. Who benefits: Defenders benefit from a clear mitigation path: apply Microsoft’s April security update, or restrict the relevant UDP traffic where immediate patching is not possible. Federal civilian agencies also have a concrete remediation deadline from CISA. Who's exposed: Organizations running unpatched supported Windows 10, Windows 11, or Windows Server systems with IKEv2 enabled are the exposed population described in the report. The cluster does not identify specific victims, sectors, or threat actors.