Microsoft announced fixes for 394 CVEs on Tuesday, including a serious flaw that has been used by hackers as a zero-day. The security flaw called CVE-2026-68820 is a use-after-free bug in the Ancillary Function Driver for WinSock (afd.sys). This driver works in kernel mode and is essential for the Windows Sockets API.
| CVE | Affected component | Impact | Severity | Publicly disclosed | Exploited in the wild |
|---|---|---|---|---|---|
| CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) |
Tampering | Important | Yes | No |
| CVE-2026-62832 | Windows User Profile Service | Elevation of Privilege | Important | Yes | No |
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | Elevation of Privilege | Important | No | Yes |
Microsoft says hackers have been using the security flaw to gain System access, but they did not provide details about the attacks.
“A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required,” the tech giant explains.
Tenable’s senior engineer Satnam Narang says that past methods used to target afd.sys flaws suggest that nation-state hackers may have used the CVE.
“Since 2022, there have been three other afd.sys zero-days exploited in the wild, including CVE-2025-32709, CVE-2025-21418, and CVE-2024-38193. CVE-2024-38193 was reportedly exploited by North Korean hackers linked to the Lazarus group,” Narang said.
As part of the August 2026 Patch Tuesday update, Microsoft pointed out CVE-2026-62832. This is a bug in Windows’s User Profile Service that has a problem with link resolution before file access. This could let attackers gain higher privileges on the system.
“An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required,” Microsoft says.
CVE-2026-72971 is a link issue in the Windows Container Isolation FS Filter Driver (unionfs.sys). This problem could allow local tampering. It was marked as publicly known, but Microsoft thinks it probably won’t be used by attackers.
| Vulnerability impact | Vulnerabilities patched |
|---|---|
| Elevation of Privilege | 150 |
| Remote Code Execution | 132 |
| Information Disclosure | 66 |
| Spoofing | 21 |
| Denial of Service | 12 |
| Security Feature Bypass | 9 |
| Tampering | 4 |
| Total | 394 |
Defenders should also watch out for other problems like CVE-2026-62878, CVE-2026-62893, CVE-2026-62815, and CVE-2026-59124. These are remote code execution (RCE) issues in Windows DNS server, Windows Deployment Services TFTP server, Microsoft QUIC, and Microsoft HPC Pack. There is also CVE-2026-62911, which is an EoP in Exchange Server, according to ZDI’s Dustin Childs.
Microsoft’s August 2026 security updates fix 236 problems in Windows, 98 in Office, 98 in Office 2016, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, 7 in Exchange Server, 1 in Defender, and 6 in other products.
The updates also have fixes for two non-Microsoft CVEs. One is a spoofing bug (CVE-2026-6726) and the other is an information leak issue (CVE-2026-6727) in the TPM 2.0 reference implementation.
InfoSecBulletin Cybersecurity for mankind
