Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [incident, patch-tuesday, microsoft, zero-day, rce, lpe, windows] ยท confidence: high ยท affected_sectors: [technology, government, finance, healthcare, energy, defence] ยท au_impact: true

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft's August security release closes 398 CVEs โ€” 62 rated Critical per ZDI โ€” including CVE-2026-68820 (CVSS 7.0), a use-after-free in afd.sys under active exploitation, and four unauthenticated CVSS 9.8 remote code execution flaws.

Summary

Microsoft's August 2026 Patch Tuesday is the largest monthly release in years by ZDI's tally. The only bug Microsoft flags as under active exploitation is CVE-2026-68820, a use-after-free in the afd.sys Ancillary Function Driver for WinSock that lets an attacker with code already running on a machine escalate to SYSTEM; Check Point Research attributes that exploit to the Lazarus Group's Operation Dream Job campaign.

The release also ships four unauthenticated remote-code-execution flaws at CVSS 9.8:

  • CVE-2026-62878 โ€” Windows DNS Server (stack buffer overflow, described by ZDI as wormable)
  • CVE-2026-62893 โ€” Windows Deployment Services (via TFTP)
  • CVE-2026-62815 โ€” Microsoft QUIC
  • CVE-2026-59124 โ€” HPC Pack

Plus the RCE half of an on-premises SharePoint chain whose authentication bypass was patched in July โ€” the two must be installed together.

Date

  • Release: 2026-08-11

Source

Related Pages