CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
CISA has added the actively exploited Windows vulnerability CVE-2026-68820 to its Known Exploited Vulnerabilities (KEV) catalog, enforcing strict remediation timelines under Binding Operational Directive 26-04. This use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) allows local privilege escalation to SYSTEM without user interaction, impacting both internal and internet-facing systems. Microsoft released fixes in cumulative updates KB5121003 and KB5120249 on August 11, 2026, but organizations must ensure affected endpoints are rebooted to complete remediation, as the vulnerable driver remains active until a restart occurs.
Executive Summary
CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires affected endpoints to reboot. Qualys AI-Powered Patch Reliability Scoring rates the KB5121003 and KB5120249 updates high for reliability, while Qualys TruRisk Eliminate helps teams deploy the update, enforce the required reboot, and verify that remediation is complete within the required timeline.…