preloader

· · digital-security devops cve cisa-kev vpn network-security windows patch-management europe

A Four-Month-Old Windows VPN Patch Just Became Urgent, CISA Confirms Active Exploitation

Source: The Hacker News

A patch that sat unremarkable for four months just became one of the more urgent items on every Windows admin’s list, because CISA has now confirmed someone is using it to break into VPN gateways.

A patch that sat quietly for four months

Microsoft fixed CVE-2026-33824 back in its April 2026 Patch Tuesday release, a double-free vulnerability in the Windows IKE (Internet Key Exchange) Service Extensions that occurs when the system mishandles memory deallocation while processing IKEv2 packets. Rated 9.8 on the CVSS scale, it lets an unauthenticated attacker send specially crafted network packets to a Windows-based VPN endpoint and achieve full remote code execution, no credentials and no user interaction required. For four months it was one more entry in a long list of critical-but-unexploited flaws. That status ended on August 18, when CISA added it to the Known Exploited Vulnerabilities catalog as part of a batch that also covered actively exploited macOS, SharePoint and vCenter flaws, confirming that theoretical severity had turned into a real attack in progress.

Hands on keyboard, not spray and pray

Palo Alto Networks’ Unit 42 traced the exploitation to a Chinese-speaking threat actor who manually sent reverse-shell callback attempts against three specific IKE VPN endpoints. That detail matters more than the CVSS score does. This was not an automated scanner sweeping the internet for anything with port 500 open, it was an operator selecting particular VPN concentrators and working the exploit chain by hand against each one. That pattern is far more consistent with espionage staging or initial access brokering than with ransomware crews casting a wide net, and it means the organizations targeted were chosen deliberately, for whatever sits on the other side of the tunnel their VPN protects.

The VPN gateway blind spot in patch management

VPN endpoints occupy an awkward spot in most patching programs: they are internet-facing by design, business-critical enough that maintenance windows get postponed, and rarely covered by the same endpoint detection tooling that watches laptops and servers. A four-month gap between an available patch and confirmed exploitation is not unusual for infrastructure that admins are reluctant to touch outside a scheduled window, but this incident is a reminder that “critical but not yet seen in the wild” is not a status that holds indefinitely, and that VPN gateways deserve the same patch urgency as internet-facing web applications, not less.

If your organization runs Windows-based VPN infrastructure and you are not certain every gateway has this patch applied, or you want a broader review of how exposed your remote access infrastructure is, contact Excello Digital. We help European businesses close the gap between “patch available” and “patch applied everywhere.”

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!