Critical CVE-2026-33824, CVE-2026-68820, CVE-2026-56155 — Three more Windows vulnerabilities joined CISA's exploited list this summer: a 9.8 remote code execution in the IKE (IPsec/VPN) service, a WinSock driver privilege escalation, and an AD FS flaw. Fixed builds and firewall mitigations.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: CVE-2026-33824 lets an unauthenticated attacker run code on Windows over the network through the IKE service (IPsec VPN key exchange, UDP 500/4500). It was fixed in April but is now being exploited. CVE-2026-68820 (WinSock driver) and CVE-2026-56155 (AD FS) let attackers who are already in escalate. Install the latest cumulative update on every PC and server, and block UDP 500/4500 anywhere you don't run IPsec.
| CVE-2026-33824 | IKE Service Extensions double free → unauthenticated remote code execution, CVSS 9.8. KEV 2026-08-18 |
|---|---|
| CVE-2026-68820 | Ancillary Function Driver for WinSock (afd.sys) use-after-free → local elevation to SYSTEM, CVSS 7.0. Zero-day, KEV 2026-08-11 |
| CVE-2026-56155 | AD FS access-control flaw → local privilege escalation, CVSS 7.8. Zero-day, KEV 2026-07-14 |
| Affected | Windows 10, Windows 11 23H2–26H1, Windows Server 2012–2025 (varies per CVE) |
| Fixed | April 2026 (33824), July 2026 (56155), August 2026 (68820) updates and later |
afd.sys, the kernel driver behind Windows networking sockets. It was exploited as a zero-day: malware already running as a normal user uses it to become SYSTEM.Check the build with winver, or in PowerShell:
$v = Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion'
"$($v.DisplayVersion) build $($v.CurrentBuild).$($v.UBR)"
You’re covered for all three once you’re at or above the build in the right-hand column (the August 2026 fix for afd.sys is the newest):
| Version | IKE fix (33824) | All three fixed |
|---|---|---|
| Windows 11 24H2 / 25H2 | 26100/26200.8246 | 26100/26200.9168 |
| Windows 11 23H2 | 22631.6936 | 22631.7517 |
| Windows 11 26H1 | 28000.1836 | 28000.2704 |
| Windows 10 22H2 / 21H2 | 19045/19044.7184 | 19045/19044.7663 |
| Windows Server 2025 | 26100.32690 | 26100.33296 |
| Windows Server 2022 | 20348.5020 | 20348.5499 |
| Windows Server 2019 | 17763.8644 | 17763.9121 |
| Windows Server 2016 | 14393.9060 | 14393.9418 |
Server 2012 / 2012 R2 receive the afd.sys and AD FS fixes only with Extended Security Updates. Windows 10 likewise needs ESU (see the Windows 10 problem).
Is IKE even listening? On a server:
Get-NetUDPEndpoint -LocalPort 500,4500 -ErrorAction SilentlyContinue
Get-Service IKEEXT
Install the latest cumulative update (any month from August 2026 onward includes all three fixes) and reboot. Prioritise:
IKEEXT) can be disabled. Test first, because some VPN and Always On VPN setups depend on it.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.