Microsoft IKE CVE-2026-33824: When an Autonomous AI Drives the Exploitation Campaign
> TL;DR: CVE-2026-33824 (CVSS 9.8) is a double-free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions, enabling unauthenticated remote code execution. What makes this case particularly notable isn't the flaw itself, but how it was exploited: a Chinese threat actor let the DeepSeek AI model, via the Hermes Agent framework, autonomously identify and target more than 460 organizations.
The technical flaw
A double-free (double memory deallocation) vulnerability in Microsoft's IKE Service Extensions — a core component of IPsec-based VPNs — allows an unauthenticated remote attacker to execute arbitrary code. CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026.
What sets this campaign apart: offensive AI autonomy
According to analysis by Palo Alto Networks Unit 42, the actor — based in Zhuhai, China, and operating under the aliases knaithe and KnYuan — used DeepSeek as an autonomous offensive operator. The observed sequence is telling:
In total, the actor attempted to compromise more than 460 targets combining autonomous and manual techniques.
Why this is a warning for every vendor, not just the direct targets
This campaign illustrates a shift in the nature of the threat that we cover regularly: AI agents are no longer just assisting a human operator — they're making autonomous decisions about reconnaissance, target selection, and adapting after a failure. The gap between a failed exploitation attempt and the pivot to another target is now measured in minutes, not days. For any internet-exposed organization, that means your entire attack surface (not just the most obvious systems) can be probed near-instantly and systematically.
What to do
What CleanIssue checks for
Our audits include a review of the exposure of your network and automation components, accounting for the fact that the gap between disclosure and exploitation is shrinking, partly driven by AI-assisted attack tooling.
Key takeaways
Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.
Related articles
Three adjacent analyses to keep exploring the same attack surface.
SonicWall SMA 1000 CVE-2026-15409: A CVSS 10.0 Flaw Exploited by INC Ransomware
CVE-2026-15409 (CVSS 10.0), an unauthenticated SSRF in SonicWall SMA 1000 VPN gateways, chained with a code injection flaw to gain root access. The INC ransomware group has made it its primary entry vector since early August 2026.
LiteLLM CVE-2026-42271: command injection via MCP endpoints, actively exploited
A flaw in the LiteLLM proxy (CVSS 8.8) lets any API key holder execute commands on the server through the MCP test endpoints. CISA confirms active exploitation. If your SaaS has AI features, read this.
SharePoint CVE-2026-55040 + CVE-2026-63520: The RCE Chain Found by an AI Agent
Two chained flaws (JWT bypass + RCE) enable unauthenticated full takeover of on-premise SharePoint. Over 8,500 internet-facing servers exposed, public PoC exploited within 24 hours.
Sources
Related services
If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.