mimile
Back to feed

Microsoft August Update Fixes Over 400 Flaws, One Exploited Zero-Day

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Microsoft August Update Fixes Over 400 Flaws, One Exploited Zero-Day

Microsoft on Tuesday released its August 2026 Patch Tuesday updates, fixing more than 400 security flaws, including one vulnerability actively exploited in the wild. The zero-day, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver (afd.sys) that allows an authenticated attacker to escalate privileges to SYSTEM. The company also flagged two other publicly disclosed flaws that it expects to be targeted in attacks.

Actively Exploited Vulnerability

The exploited flaw, CVE-2026-68820, stems from a use-after-free condition in afd.sys, the kernel-mode driver underlying the Windows Sockets API. An authenticated attacker could trigger a race condition via a specially crafted application, gaining SYSTEM privileges without user interaction. Tenable senior staff research engineer Satnam Narang noted that this marks the fourth afd.sys zero-day exploited in the wild since 2022, following CVE-2025-32709, CVE-2025-21418, and CVE-2024-38193, the last reportedly used by North Korean Lazarus group hackers. The pattern suggests potential involvement of nation-state threat actors, though Microsoft has not disclosed details on the observed attacks.

Other Critical Flaws and Update Scope

Microsoft also highlighted CVE-2026-62832, an improper link resolution in the Windows User Profile Service that could allow an authenticated attacker to load another user’s registry hive and gain administrator privileges. The company assesses it as likely to be exploited. Another publicly disclosed bug, CVE-2026-72971, a link following issue in the Windows Container Isolation FS Filter Driver, was judged unlikely to be actively exploited. Additional critical patches address remote code execution bugs in Windows DNS Server, Windows Deployment Services TFTP, Microsoft QUIC, and HPC Pack, as well as an elevation-of-privilege flaw in Exchange Server. According to SecurityWeek, the update resolves a total of 421 CVEs, including 236 Windows flaws, 98 in Office and Office 2016, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, 7 in Exchange Server, and 1 in Defender. BleepingComputer reported a total of 400 flaws, reflecting different counting methodologies.

What's Next

Microsoft urges users and organizations to prioritize patching the actively exploited zero-day. Security researchers caution that the afd.sys vulnerability may have been used by nation-state actors, but the full scope and impact of the exploitation remain unclear.