Microsoft August 2026 Patch Tuesday Addresses WinSock Zero-Day Actively Exploited in the Wild

Microsoft's August 2026 Patch Tuesday includes fixes for 421 vulnerabilities, with 62 rated critical. Notably, one zero-day vulnerability, CVE-2026-68820, a use-after-free bug in the Ancillary Function Driver for WinSock (afd.sys), has been actively exploited in the wild, reportedly by North Korea's Lazarus Group to achieve SYSTEM privileges. Two other publicly disclosed zero-days, an elevation of privilege flaw in the Windows User Profile Service (CVE-2026-62832) and a link-following bug in the Container Isolation driver (CVE-2026-72971), were also patched. Security teams are urged to prioritize these emergency fixes.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai