Microsoft August 2026 Patch Tuesday fixes 400 flaws, including exploited Windows zero-day CVE-2026-68820

Microsoft released August 2026 security updates fixing 400 vulnerabilities across Windows and other products, including one zero-day already used in attacks. The exploited flaw, CVE-2026-68820, is a use-after-free bug in the Windows Ancillary Function Driver for WinSock that can let a local authenticated attacker gain SYSTEM privileges; Check Point says Lazarus used it to deploy a new FudModule rootkit. Microsoft also fixed two publicly disclosed zero-days, including CVE-2026-62832 in the Windows User Profile Service.
Why it matters: This is a high-priority patch cycle because one bug was used in real attacks and the updates cover a very large number of serious Windows flaws. Organizations and users should prioritize testing and deploying Microsoft’s August updates, especially on Windows systems where local privilege-escalation bugs can turn an initial foothold into full device compromise.

Sources

Lazarus hackers exploited Windows zero-day to target defense firms
Bill Toulas 2026.08.12 93% relevant
This article adds attribution and exploitation context for CVE-2026-68820, saying Lazarus used the Windows AFD.sys privilege-escalation zero-day in Operation Dream Job against defense, aerospace, and aviation targets, including use of the FudModule rootkit and the Troy backdoor.
Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
2026.08.12 95% relevant
This article covers the same August 2026 Microsoft Patch Tuesday event and adds detail that the release contains 419 vulnerabilities, 62 critical and 357 important issues, plus context on two publicly disclosed zero-days and the link between exploited CVE-2026-68820 and a Lazarus job-lure campaign targeting defense, aerospace, and aviation applicants.
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
2026.08.12 95% relevant
This adds that CISA has now added CVE-2026-68820 to the federal remediation list with an August 25 deadline, and ties the in-the-wild exploitation to Lazarus Group's Dream Job campaign using fake recruiter lures and malicious PDFs against defense and aerospace targets.
Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
Ionut Arghire 2026.08.12 97% relevant
This article adds the attack attribution and intrusion details behind CVE-2026-68820, saying Lazarus exploited the Windows afd.sys zero-day in Operation Dream Job to gain SYSTEM privileges and deploy Mistpen, ForestTiger, Troy, and RelayShell against defense, aerospace, and aviation targets.
421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one
2026.08.11 93% relevant
This adds that the August Patch Tuesday total was 421 Microsoft bugs, and more importantly that Check Point observed Lazarus exploiting CVE-2026-68820 from early June in Operation Dream Job, using fake Lockheed Martin and Enveil job lures, trojanized SecurityPDF, the Troy backdoor, and a new FudModule rootkit variant.
Microsoft Plugs Nearly 400 Security Holes
BrianKrebs 2026.08.11 98% relevant
This is the same underlying August 2026 Patch Tuesday event and adds reporting detail on the scope of fixes (398 total, 42 critical), the exploited zero-day CVE-2026-68820 in afd.sys, and the two publicly disclosed issues CVE-2026-62832 and CVE-2026-72971.
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
info@thehackernews.com (The Hacker News) 2026.08.11 96% relevant
This article appears to cover the same August 2026 Microsoft Patch Tuesday event, reporting roughly the same flaw count and highlighting an actively exploited Windows driver zero-day as part of the release.
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Ionut Arghire 2026.08.11 97% relevant
This article covers the same August 2026 Patch Tuesday event and adds specifics on the scale of the release (421 CVEs), the exploited zero-day CVE-2026-68820 in afd.sys, and other notable publicly disclosed and high-priority flaws including CVE-2026-62832, CVE-2026-72971, Windows DNS Server, Exchange Server, and Microsoft QUIC issues.
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Lawrence Abrams 2026.08.11 100% relevant
This article establishes the broader August 2026 Microsoft Patch Tuesday event and introduces a separate tracked development: the actively exploited Windows zero-day CVE-2026-68820 tied by Check Point to Lazarus and FudModule deployment.
← Back to all stories