The patch window closed before most change boards met. CISA added a Windows Internet Key Exchange (IKE) Extension remote code execution bug to the Known Exploited Vulnerabilities catalog after seeing it used. BleepingComputer walked the same day: no click required on some IPsec/VPN setups. That is the outcome. The rewind is why shops still treat IKE as furniture.
IKE sits under the VPN you sold as "the secure path." It negotiates keys for IPsec. When that code is wrong, the attacker does not need a phishing PDF. They need a reachable service and a packet. Federal agencies get a hard date. Everyone else gets a blog post and a hope that WSUS ran.
What we check first
Which boxes still terminate IPsec on Windows. RRAS leftovers. Always On VPN. A vendor appliance that is "Windows under the hood" and has not had a firmware story in two years. If you cannot name the host, you cannot name the risk.
Then we ask who would notice a new child process on that host at 03:10. If the answer is "the weekly report," you do not have managed security services. You have a log subscription.
Patch is necessary. Patch is not the whole job. The same week Krebs wrote about DecryptAds, a free way to see who is in your ad supply chain. Different problem, same habit: a control you set once and never look at again.
What a finding should say
Name the listener, the build, and the proof you actually patched. "VPN should be updated" is not a finding. "vpn-edge-02 is build X; IKE Extension KB is missing; outbound RDP appeared 40 minutes after a scan from Y" is a finding.
If you already pay for an EDR, we still watch the gap between "update approved" and "update installed on the host that faces the internet." That gap is where KEV entries earn their keep.
Mail has the same shape. We already wrote that SMTP is still the front door. IKE is the side door you forgot you opened for site-to-site.
We watch the edge after the ticket closes. If you want that as a retainer, request a quote for website monitoring and host telemetry on the boxes that still speak IPsec.
Sources
- Critical RCE flaw in Windows IKE Extension now actively exploited — BleepingComputer, 19 Aug 2026
- Who's Tracking You? Use This New Service to Find Out — Krebs on Security, 14 Aug 2026

