CVE Tools
Back to feed
Exploited in the wild Windows Lazarus group nation-state Ancillary Function Driver for WinSock Microsoft

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

Microsoft has released its August 2026 security updates to address 421 vulnerabilities, notably including a high-severity zero-day in Ancillary Function Driver for WinSock identified as CVE-2026-68820. This use-after-free defect allows local attackers to achieve SYSTEM-level privileges without user interaction and is currently being exploited in the wild. Analysts suggest potential involvement from nation-state actors, drawing parallels to previous incidents targeting the same component attributed to the Lazarus group. The update cycle also resolves significant risks in Windows DNS and Exchange Server, alongside broader fixes across Office and Azure products.