
For home users, this means that if a security update is available for their device, it should be installed as soon as possible. Organizations and system administrators should also check whether affected systems are accessible via the internet and whether there are any indications that an attack has already taken place on vulnerable devices.
Microsoft IKE: Critical vulnerability enables code execution
The first vulnerability is designated CVE-2026-33824 and affects the Internet Key Exchange (IKE) service extensions in Windows. It’s caused by a “double-free” error, where a memory block can be freed multiple times under certain conditions.
The vulnerability is classified as critical, with a CVSS score of 9.8 out of 10. An unauthenticated attacker can exploit it over the network and thereby execute their own code on an affected system.
Microsoft already patched this vulnerability with its April security update. Its inclusion in the CISA KEV catalog now indicates that this risk is no longer merely theoretical—anyone who hasn’t yet installed the April Windows updates should do so ASAP. It affects various versions of Windows 10, Windows 11, and Windows Server.
Microsoft SharePoint: Attackers can bypass security feature
Microsoft SharePoint’s vulnerability CVE-2026-55040 allows unauthenticated attackers to bypass a security feature over the network. Microsoft has rated the vulnerability as critical, with a CVSS score of 9.1.
Affected systems include SharePoint Enterprise Server 2016, SharePoint Server 2019, and the Subscription Edition. Fixed builds are already available for the respective versions.