Close Menu
NCIJ Network NCIJ Network
    What's Hot

    N Korea launches ballistic missile as S Korea, US plan military drills | Weapons News

    August 12, 2026

    5 Things to Know About Francesca Hong, the Progressive Running for Wisconsin Governor

    August 12, 2026

    Saber denies replacing Rideshare Stimulator’s writers with ChatGPT

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • N Korea launches ballistic missile as S Korea, US plan military drills | Weapons News
    • 5 Things to Know About Francesca Hong, the Progressive Running for Wisconsin Governor
    • Saber denies replacing Rideshare Stimulator’s writers with ChatGPT
    • Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
    • Goliath Ventures Faces SEC, CFTC Suits Over $400M Ponzi
    • NASA Shares Station Research Today Supporting Moon, Mars Tomorrow
    • On ivory, follow the trafficking networks and not the headlines (commentary)
    • Aker BP and Equinor’s latest North Sea wildcat drilling yields no hydrocarbon find
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Microsoft on Tuesday announced patches for 421 CVEs, including a high-severity vulnerability that has been exploited in the wild as a zero-day.

    The exploited flaw, tracked as CVE-2026-68820, is described as a use-after-free issue in Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver functioning as the backbone for the Windows Sockets API.

    Microsoft says threat actors have been exploiting the security defect to elevate their privileges to System, without sharing details on the observed attacks.

    “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required,” the tech giant explains.

    According to Tenable senior staff research engineer Satnam Narang, based on historical tradecraft targeting afd.sys flaws, the CVE might have been exploited by nation-state threat actors.

    “Since 2022, there have been three other afd.sys zero-days exploited in the wild, including CVE-2025-32709, CVE-2025-21418, and CVE-2024-38193. CVE-2024-38193 was reportedly exploited by North Korean hackers linked to the Lazarus group,” Narang said.

    Advertisement. Scroll to continue reading.

    As part of the August 2026 Patch Tuesday release, Microsoft also drew attention to CVE-2026-62832, an improper link resolution before file access (link following) bug in Windows’s User Profile Service, which could allow attackers to elevate their privileges locally.

    “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required,” Microsoft says.

    The tech giant flagged the security defect as publicly disclosed and believes that threat actors are likely to start exploiting it in attacks.

    CVE-2026-72971, a link following in the Windows Container Isolation FS Filter Driver (unionfs.sys) that could lead to local tampering, was also flagged as publicly disclosed, but Microsoft believes it is unlikely to be exploited in the wild.

    Other flaws that defenders should pay attention to include CVE-2026-62878, CVE-2026-62893, CVE-2026-62815, and CVE-2026-59124, which are remote code execution (RCE) bugs in Windows DNS server, Windows Deployment Services TFTP server, Microsoft QUIC, and Microsoft HPC Pack, as well as CVE-2026-62911, an EoP in Exchange Server, ZDI’s Dustin Childs notes.

    In total, Microsoft’s August 2026 security updates resolve 236 vulnerabilities in Windows, 98 in Office, 98 in Office 2016, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, 7 in Exchange Server, 1 in Defender, and 6 in other products.

    The updates also include fixes for two non-Microsoft CVEs, namely a spoofing bug (CVE-2026-6726) and an information disclosure issue (CVE-2026-6727) in the TPM 2.0 reference implementation.

    Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

    Related: Zoom Patches Zero-Click Code Execution Vulnerability

    Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

    Related: Microsoft, Apple Release Fresh Security Updates

    August CVEs Exploited Fixes Microsoft patch Tuesday ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

    DeadLock ransomware uses blockchain to resist infrastructure takedown

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Will Andy Burnham’s everyday fixes be enough to get the public on his side? | Andy Burnham

    Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

    Cisco warns of ASA and FTD VPN flaw exploited to crash devices

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    N Korea launches ballistic missile as S Korea, US plan military drills | Weapons News

    August 12, 2026

    5 Things to Know About Francesca Hong, the Progressive Running for Wisconsin Governor

    August 12, 2026

    Saber denies replacing Rideshare Stimulator’s writers with ChatGPT

    August 12, 2026

    Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

    August 12, 2026
    Latest Posts

    I grew up near Andy Burnham. This is what shaped our new PM | Andy Burnham

    July 25, 2026

    The Economic Philosophy of Britain’s Andy Burnham

    July 25, 2026

    Samsung Wallet Will Add Stablecoin Support, Including USDC

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    N Korea launches ballistic missile as S Korea, US plan military drills | Weapons News

    August 12, 2026

    5 Things to Know About Francesca Hong, the Progressive Running for Wisconsin Governor

    August 12, 2026

    Saber denies replacing Rideshare Stimulator’s writers with ChatGPT

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.