Back to blog
CVEAI & LLMnetworkthreat

Microsoft IKE CVE-2026-33824: When an Autonomous AI Drives the Exploitation Campaign

Published on 2026-08-186 min readCleanIssue

> TL;DR: CVE-2026-33824 (CVSS 9.8) is a double-free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions, enabling unauthenticated remote code execution. What makes this case particularly notable isn't the flaw itself, but how it was exploited: a Chinese threat actor let the DeepSeek AI model, via the Hermes Agent framework, autonomously identify and target more than 460 organizations.

The technical flaw

A double-free (double memory deallocation) vulnerability in Microsoft's IKE Service Extensions — a core component of IPsec-based VPNs — allows an unauthenticated remote attacker to execute arbitrary code. CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026.

What sets this campaign apart: offensive AI autonomy

According to analysis by Palo Alto Networks Unit 42, the actor — based in Zhuhai, China, and operating under the aliases knaithe and KnYuan — used DeepSeek as an autonomous offensive operator. The observed sequence is telling:

  • A failed initial attempt: the AI agent tries to exploit a Langflow flaw (CVE-2026-33017), but fails due to restrictive configurations on the target environment.
  • Autonomous search for alternative targets: rather than giving up, the AI agent conducts its own research to identify other higher-value vulnerabilities, including in n8n.
  • Resource-conscious targeting: the actor let DeepSeek narrow the targeting scope, likely to conserve AI compute — a process that would have required hundreds of hours of manual analysis, executed in minutes.
  • Parallel manual operations: the same actor conducted manual attacks exploiting known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and the IKE service (CVE-2026-33824).
  • In total, the actor attempted to compromise more than 460 targets combining autonomous and manual techniques.

    Why this is a warning for every vendor, not just the direct targets

    This campaign illustrates a shift in the nature of the threat that we cover regularly: AI agents are no longer just assisting a human operator — they're making autonomous decisions about reconnaissance, target selection, and adapting after a failure. The gap between a failed exploitation attempt and the pivot to another target is now measured in minutes, not days. For any internet-exposed organization, that means your entire attack surface (not just the most obvious systems) can be probed near-instantly and systematically.

    What to do

  • Patch CVE-2026-33824 as soon as possible on any system exposing the IKE/IPsec VPN service.
  • Don't stop at the most publicized flaw: also audit the neighboring systems mentioned in this campaign (Citrix NetScaler, Apache Tomcat, automation platforms like n8n) if you run them.
  • Shorten your patch turnaround on internet-exposed components — against partially automated exploitation campaigns, every day of delay now matters more than it used to.
  • What CleanIssue checks for

    Our audits include a review of the exposure of your network and automation components, accounting for the fact that the gap between disclosure and exploitation is shrinking, partly driven by AI-assisted attack tooling.

    Key takeaways

  • Offensive AI agents can now autonomously pivot to an alternative target after a failure, drastically cutting manual reconnaissance time.
  • A single campaign can combine AI-driven automated exploitation with manual operations on known vulnerabilities — defense must cover both fronts.
  • Patch management now needs to operate on an hours-scale tempo for internet-exposed components, not a weeks-scale one.
  • Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit