Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Windows IKE RCE CVE-2026-33824 and AFD Zero-Day CVE-2026-68820: Exploited Windows Bugs, Summer 2026

Critical CVE-2026-33824, CVE-2026-68820, CVE-2026-56155 — Three more Windows vulnerabilities joined CISA's exploited list this summer: a 9.8 remote code execution in the IKE (IPsec/VPN) service, a WinSock driver privilege escalation, and an AD FS flaw. Fixed builds and firewall mitigations.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: CVE-2026-33824 lets an unauthenticated attacker run code on Windows over the network through the IKE service (IPsec VPN key exchange, UDP 500/4500). It was fixed in April but is now being exploited. CVE-2026-68820 (WinSock driver) and CVE-2026-56155 (AD FS) let attackers who are already in escalate. Install the latest cumulative update on every PC and server, and block UDP 500/4500 anywhere you don't run IPsec.

CVE-2026-33824IKE Service Extensions double free → unauthenticated remote code execution, CVSS 9.8. KEV 2026-08-18
CVE-2026-68820Ancillary Function Driver for WinSock (afd.sys) use-after-free → local elevation to SYSTEM, CVSS 7.0. Zero-day, KEV 2026-08-11
CVE-2026-56155AD FS access-control flaw → local privilege escalation, CVSS 7.8. Zero-day, KEV 2026-07-14
AffectedWindows 10, Windows 11 23H2–26H1, Windows Server 2012–2025 (varies per CVE)
FixedApril 2026 (33824), July 2026 (56155), August 2026 (68820) updates and later

The three bugs

  • CVE-2026-33824, IKE Service Extensions RCE. IKE is the key-exchange protocol behind IPsec VPNs and Windows’ built-in VPN/DirectAccess. A double free lets an unauthenticated attacker who can reach UDP 500/4500 run code on the machine. Microsoft patched it in April 2026. CISA added it to the exploited list in August, meaning attackers built a working exploit from the patch and are now using it on machines that never updated.
  • CVE-2026-68820, WinSock driver EoP. A use-after-free in afd.sys, the kernel driver behind Windows networking sockets. It was exploited as a zero-day: malware already running as a normal user uses it to become SYSTEM.
  • CVE-2026-56155, AD FS EoP. On servers running Active Directory Federation Services (the role that provides single sign-on for many on-prem and hybrid setups), coarse access control let an authenticated attacker escalate locally. Also a zero-day.

Am I affected?

Check the build with winver, or in PowerShell:

$v = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
"$($v.DisplayVersion)  build $($v.CurrentBuild).$($v.UBR)"

You’re covered for all three once you’re at or above the build in the right-hand column (the August 2026 fix for afd.sys is the newest):

VersionIKE fix (33824)All three fixed
Windows 11 24H2 / 25H226100/26200.824626100/26200.9168
Windows 11 23H222631.693622631.7517
Windows 11 26H128000.183628000.2704
Windows 10 22H2 / 21H219045/19044.718419045/19044.7663
Windows Server 202526100.3269026100.33296
Windows Server 202220348.502020348.5499
Windows Server 201917763.864417763.9121
Windows Server 201614393.906014393.9418

Server 2012 / 2012 R2 receive the afd.sys and AD FS fixes only with Extended Security Updates. Windows 10 likewise needs ESU (see the Windows 10 problem).

Is IKE even listening? On a server:

Get-NetUDPEndpoint -LocalPort 500,4500 -ErrorAction SilentlyContinue
Get-Service IKEEXT

How to patch

Install the latest cumulative update (any month from August 2026 onward includes all three fixes) and reboot. Prioritise:

  1. Anything with UDP 500/4500 reachable from the internet: VPN servers, RRAS, DirectAccess, servers with a public IP.
  2. AD FS servers.
  3. Everything else.

Mitigations

  • Block inbound UDP 500 and 4500 at the edge firewall for every host that isn’t an IPsec VPN endpoint. Most PCs and servers have no reason to accept IKE from the internet.
  • If a server doesn’t use IPsec at all, the IKE and AuthIP IPsec Keying Modules service (IKEEXT) can be disabled. Test first, because some VPN and Always On VPN setups depend on it.
  • For the two privilege-escalation bugs there’s no workaround; they’re only reachable once an attacker already runs code, so endpoint protection and least privilege are your buffer until you patch.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories