Microsoft has released its monthly security updates for August, fixing hundreds of vulnerabilities across its products, including a Windows flaw that is already being exploited in attacks.
The actively exploited vulnerability, tracked as CVE-2026-68820 with a CVSS score of 7.0, affects a core Windows kernel driver responsible for network socket operations. An attacker who already has code running on a vulnerable system can exploit the flaw to elevate privileges and gain SYSTEM-level access.
The vulnerability involves a race condition in the driver. Microsoft has confirmed that it is being exploited in the wild but has not publicly attributed the attacks. Check Point Research, however, said the North Korean-linked Lazarus group used the zero-day as part of its Operation Dream Job campaign.
Check Point Research identified CVE-2026-68820 as a use-after-free vulnerability in afd.sys, the Ancillary Function Driver for WinSock and a kernel-side component of Windows networking.
Although the vulnerability has a lower CVSS score than several other flaws patched this month, its active exploitation makes it a higher priority for affected Windows systems. An attacker must already have code running on the machine, but successful exploitation can allow them to move from that foothold to SYSTEM privileges.
Microsoft also patched four critical remote code execution vulnerabilities that require no authentication and no user interaction. Each carries a CVSS score of 9.8, although none was known to be exploited when Microsoft released the updates.
CVE-2026-62878 affects Windows DNS Server and involves a remotely reachable stack-based buffer overflow. The flaw can be exploited without authentication or user interaction. The Zero Day Initiative describes the technical condition as wormable, although that does not mean an actual worm exploiting the vulnerability has been observed.
CVE-2026-62893 affects Windows Deployment Services and involves a remote vulnerability in its TFTP handling. An attacker can reach the vulnerable service without authentication or requiring any action from a user.
CVE-2026-62815 affects Microsoft’s implementation of the QUIC transport protocol and can allow remote, unauthenticated code execution without user interaction.
The fourth flaw, CVE-2026-59124, affects Microsoft’s High Performance Computing Pack. It also has a CVSS score of 9.8 and can potentially be exploited remotely without authentication or user interaction. Microsoft rates it as Important rather than Critical because HPC Pack is not installed by default, while exploitation is considered more likely.
The Zero Day Initiative independently counted 398 new CVEs in Microsoft’s August release, including 62 rated Critical. The number of vulnerabilities in the release does not by itself determine which systems should be patched first, with active exploitation, affected services and network exposure also playing an important role.
The August updates also complete Microsoft’s fix for a SharePoint exploit chain that began with a vulnerability patched in July.
Rapid7 Labs reported the chain to Microsoft on May 18 after discovering that an authentication bypass could be combined with a separate code execution vulnerability to achieve unauthenticated remote code execution against on-premises SharePoint servers. Microsoft later confirmed that the fixes would be split between its July and August security updates.
The July update addressed CVE-2026-55040, a Critical authentication bypass vulnerability with a CVSS score of 9.1. The flaw could allow a remote unauthenticated attacker to assume the identity of a SharePoint user or administrator when the attacker knew the identity they wanted to impersonate.
The August update addresses CVE-2026-63520, which is the remote code execution component of the chain. The vulnerability does not independently provide the unauthenticated condition described in the full attack chain.
Rapid7 said applying the July fix for CVE-2026-55040 breaks the demonstrated attack chain. Installing the August update now also removes the underlying RCE component.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
For Windows environments, CVE-2026-68820 should be prioritized because Microsoft has confirmed active exploitation. Administrators should also assess exposed DNS Server, Windows Deployment Services, QUIC and HPC Pack installations, while organizations running on-premises SharePoint should ensure both the July authentication-bypass update and the August RCE update have been installed.





