"Exploitation Less Likely": 126 days in the queue for CVE-2026-33824
Microsoft patched the Windows IPsec VPN flaw on 14 April with the label "Exploitation Less Likely". CISA added it to its exploited catalogue on 18 August. Between those dates sit 126 days, a Unit 42 report, and a vendor page that still has not been corrected. Our own count across Microsoft's 24 KEV entries this year, and which mitigation you cannot apply if your VPN carries remote workers.