ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

Executive Summary

A zero‑day vulnerability (CVE‑2026‑50696) in Microsoft Windows allows unauthenticated remote attackers to exploit an integer underflow in the IKEv2 AES‑GCM decryption routine, enabling arbitrary code execution on systems with specific IPsec configurations. The Zero Day Initiative assigned a CVSS score of 8.1.


Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-08T05:00:00+00:00 - Category: cves

Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Authentication is not required to exploit this vulnerability, but only systems with specific IPsec configurations are vulnerable. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-50696.

"The real measure of your wealth is how much youd be worth if you lost all your money."

— Unknown
Source: Zero Day Initiative