Exploited in the wild Windows Lazarus group nation-state Ancillary Function Driver for WinSock Microsoft
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
CVE Tools coverage
Microsoft has released its August 2026 security updates to address 421 vulnerabilities, notably including a high-severity zero-day in Ancillary Function Driver for WinSock identified as CVE-2026-68820. This use-after-free defect allows local attackers to achieve SYSTEM-level privileges without user interaction and is currently being exploited in the wild. Analysts suggest potential involvement from nation-state actors, drawing parallels to previous incidents targeting the same component attributed to the Lazarus group. The update cycle also resolves significant risks in Windows DNS and Exchange Server, alongside broader fixes across Office and Azure products.