Critical Windows VPN Flaw Under Active Attack: What Perth Businesses Need to Check

CISA confirms hackers are actively exploiting a critical Windows VPN flaw, CVE-2026-33824, to break into business networks with no login required. From Computer Mechanics, Perth IT specialists since 1997.

AmirAmir · Cloud System Engineer
28 August 2026
5 min read
Cybersecurity
VPN
Windows Server
Perth Business
A padlock over a server rack representing a Windows VPN security vulnerability

If your business runs its own Windows Server to let staff connect remotely over a VPN, there's a critical flaw you need to check right now. CISA (the US Cybersecurity and Infrastructure Security Agency, whose alerts Australian businesses should treat as a global early-warning system) confirmed on 18 August that hackers are actively exploiting CVE-2026-33824, a flaw in the Windows component that handles IPsec and IKEv2 VPN connections. An attacker doesn't need a username, a password, or a phishing email to use it — just network access to the right port. Microsoft patched it back in April, but if that update was missed, your VPN server could already be exposed.

What the flaw actually does

CVE-2026-33824 sits in the Windows IKE (Internet Key Exchange) service, the part of Windows that negotiates a secure VPN tunnel before any login happens. It's a "double-free" memory bug, which sounds technical but the outcome is simple: an attacker sends specially crafted network packets to UDP port 500 or 4500 on a vulnerable Windows machine, and the flaw lets that traffic run code with full SYSTEM privileges — the highest level of access on the machine.

Rated 9.8 out of 10 on the industry severity scale, it's classed as critical for two reasons: it needs no authentication at all, and it targets a service that's often deliberately exposed to the internet, because that's the whole point of a VPN endpoint. Security researchers have already linked real-world attacks to this flaw, with reverse-shell connections observed on compromised VPN servers.

Why this matters more than a typical patch

Most critical vulnerabilities get patched quietly and never see active exploitation. This one is different: Microsoft fixed it in April 2026, but it's only now — four months later — showing up in real attacks. That gap is the dangerous part. Plenty of small and medium businesses run Windows Update on their desktops without fail, but treat their server infrastructure more cautiously, deferring updates on a machine that "just works" and hosts business-critical remote access. If your Windows Server hasn't had its updates applied since before April, this flaw may still be sitting open.

It's also a reminder that a VPN server isn't just another machine on the network — it's the front door. A successful attack here doesn't need to trick an employee into clicking anything. It goes straight past your staff and your email filtering, because it targets the server infrastructure itself.

Is your business affected?

You're potentially exposed if any of the following applies:

  • You run Windows Server with Routing and Remote Access Service (RRAS) configured for VPN, and it accepts IKEv2 or IPsec connections from outside your office network.
  • A third-party firewall or VPN appliance in your network relies on the same underlying Windows IKE service (check with whoever manages it if you're unsure).
  • Your Windows Server patching has lapsed, been paused, or been handled ad hoc rather than through a managed, monitored process.

You're likely fine if your remote access runs through a dedicated hardware firewall or a cloud-based VPN service (rather than Windows Server itself), or if your servers are on a strict, verified patch schedule that's already applied everything through April 2026 and beyond.

What to do this week

  1. Confirm the patch is installed. Check the update history on any Windows Server running RRAS or acting as a VPN endpoint. You're looking for the April 2026 cumulative update or later — if it's missing, apply it immediately, outside business hours if needed, and reboot to confirm it's taken effect.
  2. Check what's actually exposed to the internet. If UDP 500 and 4500 are open to the world on a server that doesn't need to be a VPN endpoint, that's worth reviewing regardless of this specific flaw.
  3. Look for signs of prior compromise, not just the patch. If the server has been vulnerable since April, patching now closes the door but doesn't undo anything that already happened. A quick check of server logs and any unusual admin accounts is worth doing if you can't confirm the update was applied promptly back in April.
  4. Move to a monitored patch cycle if you're not already on one. The core lesson here isn't really about one CVE — it's that server-side infrastructure needs the same disciplined, verified patching as everyday desktops, arguably more so, because it's usually the piece facing the outside world.

The bigger picture for Perth businesses

We're seeing the pattern shift industry-wide: the window between a vendor releasing a fix and criminals weaponising it against unpatched systems keeps shrinking. Waiting months to apply a server update used to be low-risk. Increasingly, it isn't. If you're not certain when your VPN or remote-access infrastructure was last patched, that uncertainty is the actual problem worth fixing, not just this one flaw.

If you manage your own on-premises server and aren't confident it's fully patched, or you'd rather have someone independently verify your remote access setup isn't exposed, our IT security solutions and on-premises server management services cover exactly this kind of check. We also review firewall configuration as part of a broader network health check, since a VPN endpoint is only as safe as the perimeter around it.

We're a Perth-based team who've been keeping local businesses running since 1997 — happy to take a look if you're unsure where you stand. Call us on (08) 9325 1196.

Amir
Written by
Amir
Cloud System Engineer · 10+ years in IT

Amir is a Cloud System Engineer with over a decade of experience across server management, networking, cloud solutions and virtualisation. He designs and secures the Microsoft 365, Azure and network environments that Perth businesses rely on, turning complex infrastructure into scalable, efficient solutions.

Meet the IT Support Perth team →
Amir
28 August 2026
5 min read
Cybersecurity
VPN
Windows Server
Perth Business

Stay Updated with IT Insights

Get the latest cybersecurity tips and technology insights delivered to your inbox

Related Articles

Scams Awareness Week 2026: Why 4 in 5 Perth Small Businesses Are Already a Target

This week's national Scams Awareness Week data shows four in five small businesses were targeted in the past year. Here's the 'Stop. Check. Protect.' test for your Perth business. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Windows 11 24H2 Stops Getting Updates in October: What Perth Businesses Should Check Now

Windows 11 version 24H2 Home and Pro editions reach end of updates on 13 October 2026. Here's how to check what your Perth business is running and what to do before then. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Hackers Breached the Software Your IT Provider Manages You With: A Perth Guide

In August 2026 attackers actively exploited a widely used remote IT management platform to reach into client networks. Here's what it means for your Perth business. From Computer Mechanics, Perth IT specialists since 1997.

5 min read

Need Expert IT Support?

Get personalized advice from our Perth IT experts. Free consultation available.

Related Content

Continue Reading

Explore more insights and expert advice on IT support, cybersecurity, and digital transformation

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.
CyberSecurity
ITSupportPerth

Your Messages Are "Encrypted" — But the FBI Just Read Them Anyway. Here's What Every Perth Business Needs to Know.

Most small business owners believe end-to-end encryption means their messages are completely private. A recent FBI case proves that assumption is dangerously incomplete.

5 min read
4/15/2026
What’s new in SMB1001:2026?
SMB1001
SMB10012026

What’s new in SMB1001:2026?

SMB1001:2026 updates for Perth SMBs: Mandatory DMARC from Silver tier, 5 maturity levels, Essential Eight alignment. Get certified, cut insurance costs, win tenders—start your roadmap today!

5 min read
2/25/2026
Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do
Cybersecurity
Patch Management

Microsoft's August 2026 Patch Tuesday Fixed a Flaw Already Under Attack: What to Do

Microsoft's August 2026 security update patched a Windows flaw that was already being exploited to seize full control of machines, plus a critical SharePoint hole. Here's what Perth businesses need to check this week. From Computer Mechanics, Perth IT specialists since 1997.

5 min read
8/12/2026
Call us