If your business runs its own Windows Server to let staff connect remotely over a VPN, there's a critical flaw you need to check right now. CISA (the US Cybersecurity and Infrastructure Security Agency, whose alerts Australian businesses should treat as a global early-warning system) confirmed on 18 August that hackers are actively exploiting CVE-2026-33824, a flaw in the Windows component that handles IPsec and IKEv2 VPN connections. An attacker doesn't need a username, a password, or a phishing email to use it — just network access to the right port. Microsoft patched it back in April, but if that update was missed, your VPN server could already be exposed.
What the flaw actually does
CVE-2026-33824 sits in the Windows IKE (Internet Key Exchange) service, the part of Windows that negotiates a secure VPN tunnel before any login happens. It's a "double-free" memory bug, which sounds technical but the outcome is simple: an attacker sends specially crafted network packets to UDP port 500 or 4500 on a vulnerable Windows machine, and the flaw lets that traffic run code with full SYSTEM privileges — the highest level of access on the machine.
Rated 9.8 out of 10 on the industry severity scale, it's classed as critical for two reasons: it needs no authentication at all, and it targets a service that's often deliberately exposed to the internet, because that's the whole point of a VPN endpoint. Security researchers have already linked real-world attacks to this flaw, with reverse-shell connections observed on compromised VPN servers.
Why this matters more than a typical patch
Most critical vulnerabilities get patched quietly and never see active exploitation. This one is different: Microsoft fixed it in April 2026, but it's only now — four months later — showing up in real attacks. That gap is the dangerous part. Plenty of small and medium businesses run Windows Update on their desktops without fail, but treat their server infrastructure more cautiously, deferring updates on a machine that "just works" and hosts business-critical remote access. If your Windows Server hasn't had its updates applied since before April, this flaw may still be sitting open.
It's also a reminder that a VPN server isn't just another machine on the network — it's the front door. A successful attack here doesn't need to trick an employee into clicking anything. It goes straight past your staff and your email filtering, because it targets the server infrastructure itself.
Is your business affected?
You're potentially exposed if any of the following applies:
- You run Windows Server with Routing and Remote Access Service (RRAS) configured for VPN, and it accepts IKEv2 or IPsec connections from outside your office network.
- A third-party firewall or VPN appliance in your network relies on the same underlying Windows IKE service (check with whoever manages it if you're unsure).
- Your Windows Server patching has lapsed, been paused, or been handled ad hoc rather than through a managed, monitored process.
You're likely fine if your remote access runs through a dedicated hardware firewall or a cloud-based VPN service (rather than Windows Server itself), or if your servers are on a strict, verified patch schedule that's already applied everything through April 2026 and beyond.
What to do this week
- Confirm the patch is installed. Check the update history on any Windows Server running RRAS or acting as a VPN endpoint. You're looking for the April 2026 cumulative update or later — if it's missing, apply it immediately, outside business hours if needed, and reboot to confirm it's taken effect.
- Check what's actually exposed to the internet. If UDP 500 and 4500 are open to the world on a server that doesn't need to be a VPN endpoint, that's worth reviewing regardless of this specific flaw.
- Look for signs of prior compromise, not just the patch. If the server has been vulnerable since April, patching now closes the door but doesn't undo anything that already happened. A quick check of server logs and any unusual admin accounts is worth doing if you can't confirm the update was applied promptly back in April.
- Move to a monitored patch cycle if you're not already on one. The core lesson here isn't really about one CVE — it's that server-side infrastructure needs the same disciplined, verified patching as everyday desktops, arguably more so, because it's usually the piece facing the outside world.
The bigger picture for Perth businesses
We're seeing the pattern shift industry-wide: the window between a vendor releasing a fix and criminals weaponising it against unpatched systems keeps shrinking. Waiting months to apply a server update used to be low-risk. Increasingly, it isn't. If you're not certain when your VPN or remote-access infrastructure was last patched, that uncertainty is the actual problem worth fixing, not just this one flaw.
If you manage your own on-premises server and aren't confident it's fully patched, or you'd rather have someone independently verify your remote access setup isn't exposed, our IT security solutions and on-premises server management services cover exactly this kind of check. We also review firewall configuration as part of a broader network health check, since a VPN endpoint is only as safe as the perimeter around it.
We're a Perth-based team who've been keeping local businesses running since 1997 — happy to take a look if you're unsure where you stand. Call us on (08) 9325 1196.



