Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Reported exploitedWindowsLazarus groupAncillary Function Driver for WinSockOur summary
Microsoft has released its August 2026 security updates, addressing 400 vulnerabilities including three zero-days. One of these, CVE-2026-68820, is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that was actively exploited by the North Korean Lazarus group to deploy the FudModule rootkit. This vulnerability allows a local attacker to escalate privileges to SYSTEM level without user interaction. The patch also resolves two other publicly disclosed elevation-of-privilege issues within the Windows User Profile Service.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.