Microsoft Patch Tuesday August 2026

Microsoft Patches Hundreds of Vulnerabilities, Including One Actively Exploited

Microsoft, Microsoft Patch Tuesday, Microsoft vulnerabilities, CVE-2026-68820, Microsoft August Patch Tuesday vulnerabilities, actively exploited Windows zero-day CVE-2026-68820, Lazarus Group Windows zero-day attack, Microsoft Patch Tuesday August 2026
Facebook
X
LinkedIn
Reddit
WhatsApp
Source: Alberto Garcia Guillen / Shutterstock.com

Microsoft has patched hundreds of vulnerabilities as part of its August Patch Tuesday release. One of the flaws was already being exploited as a zero-day by the Lazarus Group.

The actively exploited vulnerability, tracked as CVE-2026-68820 with a CVSS score of 7.0, affects afd.sys, the Ancillary Function Driver for WinSock, a core Windows kernel driver that handles virtually every network connection on Windows systems. The flaw is a use-after-free vulnerability. An attacker who is already logged into the local system can trigger a race condition through a specially crafted application and gain SYSTEM privileges without any further user interaction. The vulnerability was reported by Check Point researchers Moshe Marelus and David Driker and was already being actively exploited as a zero-day when it was disclosed.

Ad

According to Check Point Research, the North Korea-linked Lazarus Group exploited the vulnerability as part of its long-running Operation Dream Job campaign, which uses fake job offers to target victims. Most recently, the campaign has focused on organizations in the defense sector across Europe and India. The attackers initially gained access through a specially crafted PDF application called SecurityPDF and a newly discovered backdoor dubbed Troy. They then exploited the Windows vulnerability to execute a new version of their FudModule kernel rootkit with SYSTEM privileges. Security researchers say three other zero-day vulnerabilities in the same driver have been actively exploited since 2022, including a 2024 flaw also attributed to Lazarus.

Four More Critical Flaws Require No User Interaction

Microsoft also patched four additional vulnerabilities, each rated 9.8, the highest possible CVSS score. Exploiting these flaws requires neither a user account nor any interaction from the victim. The vulnerabilities affect Windows DNS Server, Windows Deployment Services, Microsoft’s implementation of the QUIC transport protocol, and the High Performance Computing Pack.

None of the four vulnerabilities was known to be actively exploited at the time of publication. The Zero Day Initiative puts the overall scope of the August Patch Tuesday release at 398 new CVE entries, independently of Microsoft’s own count, including 62 classified as critical. Microsoft itself, along with several industry publications, reports a total of 421 CVE entries.

Ad

SharePoint Attack Chain Fully Patched

The August Patch Tuesday release also closes the second half of an attack chain targeting on-premises SharePoint installations that Microsoft had only partially addressed in July. Security researchers at Rapid7 had reported a combination of an authentication bypass and a separate remote code execution vulnerability to Microsoft in May. Together, the flaws allowed attackers to execute arbitrary code without prior authentication.

In July, Microsoft initially patched the authentication bypass tracked as CVE-2026-55040. The vulnerability allowed a remote, unauthenticated attacker to impersonate any SharePoint user or administrator, provided the attacker knew the identity of the account.

The corresponding code execution vulnerability, CVE-2026-63520, has now been addressed in August. Security researchers advise operators of on-premises SharePoint farms to ensure that both the July and August updates are installed.

(Editorial Team)

Ad

Artikel zu diesem Thema

Weitere Artikel