CVE-2026-33824
As of 2026-04-14, CVE-2026-33824 is a CVSS 8.4 (HIGH-severity) vulnerability. EPSS exploitation probability 0.1%. Threadlinqs Intelligence tracks 4 threats exploiting it.
Last updated: 2026-04-14
A remote code execution vulnerability exists in Microsoft Office and Outlook due to an OLE object handling bug. An attacker could exploit this vulnerability by sending a specially crafted email; previewing the email in the Outlook Preview Pane is sufficient to trigger exploitation without requiring the user to open the message. Successful exploitation allows arbitrary code execution in the context of the user. The vulnerability was disclosed as part of the Microsoft April 2026 Patch Tuesday release, which remediated 167 vulnerabilities. This CVE was rated Critical severity with a CVSS 8.4 base score. The Preview Pane attack vector significantly increases exploitability as no user interaction beyond viewing the email preview is required.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-843
Threats tracking this CVE
- Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNS — CRITICAL
- Microsoft April 2026 Patch Tuesday — 163 CVEs / 88 Advisories (CVE-2026-32201 SharePoint Zero-Day Exploited In-The-Wild, CVE-2026-33825 Defender EoP Public PoC, CVE-2026-33824 IKE RCE CVSS 9.8, CVE-2026-33827 TCP/IP Wormable RCE) — CRITICAL
- CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Free — CRITICAL
- Microsoft April 2026 Patch Tuesday — 167 Flaws, 2 Zero-Days (SharePoint Spoofing CVE-2026-32201 + Defender EoP CVE-2026-33825) — CRITICAL
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33824
- https://nvd.nist.gov/vuln/detail/CVE-2026-33824
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.