Microsoft Addresses Zero-Day Vulnerability (CVE-2026-68820) in Windows AFD.sys Exploited by North Korean Hackers, Alongside Critical SharePoint RCE (CVE-2026-50522) Under Active Attack
Microsoft's August Patch Tuesday includes fixes for over 400 vulnerabilities, notably a critical use-after-free flaw (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (AFD.sys). This zero-day vulnerability is actively being exploited by North Korean attackers to escalate privileges to SYSTEM, prompting CISA to issue a directive for federal agencies to patch by August 25. Additionally, a critical remote code execution (RCE) vulnerability (CVE-2026-50522) in Microsoft SharePoint is also under active exploitation by state-linked and criminal threat actors, allowing unauthorized access and data theft.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai