Most Patch Tuesdays fix flaws before anyone outside Microsoft has used them. August 2026’s did not have that luxury.
What Microsoft fixed
Microsoft’s August 2026 Patch Tuesday, released 11 August, fixed 421 vulnerabilities across Windows and its wider product ecosystem, including 62 rated Critical. Three of those were zero-days, vulnerabilities disclosed or exploited before a patch existed.
The most serious, CVE-2026-68820, was already being used in real attacks before Microsoft shipped the fix. It is a use-after-free flaw in afd.sys, the kernel-mode driver behind the Windows Sockets API, that lets an attacker who already has a foothold on a device escalate to SYSTEM-level privileges, the highest level of control Windows has.
Who was using it, and for what
Security researchers at Check Point reported the North Korea-linked Lazarus group exploiting the flaw to deploy a new version of its FudModule kernel-mode rootkit, malware built specifically to operate beneath the reach of normal endpoint security tools once it has SYSTEM-level access.
Two further zero-days were disclosed in the same release without confirmed active exploitation yet: one in Windows User Profile Service, considered likely to see exploitation soon, and one in the Container Isolation FS Filter Driver.
The pattern worth watching
An actively exploited kernel-level privilege escalation being used by a known state-linked group to deploy rootkit malware is a serious combination on its own. That it landed in the same release as two more disclosed zero-days is a reminder that patch verification, not just patch deployment, needs to be a standing routine rather than a monthly event.
Talk to us about verifying your patch coverage.
Specialists in Business Applications, Modern Workplace and Azure. Let’s grow.
Sources: Microsoft Security Response Center, August 2026 Patch Tuesday release notes; Check Point Research on CVE-2026-68820 exploitation by the Lazarus group. Accurate as of publication and subject to Microsoft’s ongoing updates.