Insights

Microsoft patches a Windows zero-day already being exploited

Most Patch Tuesdays fix flaws before anyone outside Microsoft has used them. August 2026’s did not have that luxury.

What Microsoft fixed

Microsoft’s August 2026 Patch Tuesday, released 11 August, fixed 421 vulnerabilities across Windows and its wider product ecosystem, including 62 rated Critical. Three of those were zero-days, vulnerabilities disclosed or exploited before a patch existed.

The most serious, CVE-2026-68820, was already being used in real attacks before Microsoft shipped the fix. It is a use-after-free flaw in afd.sys, the kernel-mode driver behind the Windows Sockets API, that lets an attacker who already has a foothold on a device escalate to SYSTEM-level privileges, the highest level of control Windows has.

Who was using it, and for what

Security researchers at Check Point reported the North Korea-linked Lazarus group exploiting the flaw to deploy a new version of its FudModule kernel-mode rootkit, malware built specifically to operate beneath the reach of normal endpoint security tools once it has SYSTEM-level access.

Two further zero-days were disclosed in the same release without confirmed active exploitation yet: one in Windows User Profile Service, considered likely to see exploitation soon, and one in the Container Isolation FS Filter Driver.

Do this today: confirm every managed endpoint in your business has installed the August cumulative update, particularly any device that has been offline, poorly connected, or excluded from update policies. With one of these already confirmed exploited in the wild, this is not a patch to leave for later.

The pattern worth watching

An actively exploited kernel-level privilege escalation being used by a known state-linked group to deploy rootkit malware is a serious combination on its own. That it landed in the same release as two more disclosed zero-days is a reminder that patch verification, not just patch deployment, needs to be a standing routine rather than a monthly event.

Talk to us about verifying your patch coverage.

Specialists in Business Applications, Modern Workplace and Azure. Let’s grow.

Sources: Microsoft Security Response Center, August 2026 Patch Tuesday release notes; Check Point Research on CVE-2026-68820 exploitation by the Lazarus group. Accurate as of publication and subject to Microsoft’s ongoing updates.

Download your copy of the Insights

Related Posts

Azure Chaos Studio Workspaces can test a complete...

The Semi-Annual Enterprise Channel name still sounds slow....

Microsoft moved Defender Threat Intelligence into Defender XDR...