Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News

    October 3, 2026

    Surfshark Promo Codes: 87% Off | October 2026

    October 3, 2026

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News
    • Surfshark Promo Codes: 87% Off | October 2026
    • ShinyHunters hacker reportedly detained in Jordan, aiding FBI
    • Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea
    • Vitamin C linked to fewer deaths in blood disorder trial
    • Trump ramps up pressure on US Republicans to end US clock switching | Donald Trump News
    • Conservatives pledge to scrap £100,000 childcare ‘cliff edge’
    • Tories plan to expand free childcare to high earners to end ‘cliff edge’ | Conservatives
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 11, 2026Vulnerability / Windows Security

    Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.

    The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.

    The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month’s release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft has not publicly attributed the exploitation. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign.

    Four other flaws in the release need nothing at all from the victim: no account, no password, no click. They affect Windows DNS Server, Windows Deployment Services, Microsoft’s implementation of the QUIC transport protocol, and High Performance Computing (HPC) Pack, and each carries a CVSS score of 9.8. None was flagged as exploited when the updates shipped.

    Cybersecurity

    Counting independently, the Zero Day Initiative puts the release at 398 new CVEs, 62 of them rated Critical. The count shows the size of the release; exploit status and reach decide the patch order.

    The release also closes the RCE half of a SharePoint chain whose authentication bypass was fixed in July. On-premises SharePoint farms should have both updates installed.

    Check Point Research said CVE-2026-68820 is a use-after-free in afd.sys, the Ancillary Function Driver for WinSock and a kernel-side component of Windows networking.

    The bug is privilege escalation: an attacker needs code running on the machine first, then can use it to reach SYSTEM. Microsoft flags it as actively exploited, which puts it ahead of the four 9.8 server RCEs here despite the lower score.

    Nothing required from the victim

    The four unauthenticated remote code execution flaws are the ones to queue behind the exploited driver bug because they can give an attacker code on a server without first needing an account or a user action.

    • CVE-2026-62878, Windows DNS Server. A stack-based buffer overflow reachable remotely with no authentication and no user interaction. The Zero Day Initiative describes the condition as wormable despite Microsoft rating exploitation as less likely. ZDI’s “wormable” label describes the technical condition; it does not establish that a worm exists.
    • CVE-2026-62893, Windows Deployment Services. A remote flaw reachable through the service’s TFTP handling without authentication or user interaction.
    • CVE-2026-62815, Microsoft QUIC. A remote, unauthenticated code execution flaw requiring no user interaction.
    • CVE-2026-59124, HPC Pack. It carries the same 9.8 score but is rated Important rather than Critical because HPC Pack is not installed by default. Microsoft rates exploitation as more likely.
    Cybersecurity

    HPC Pack is not installed by default, and the practical priority of the other three likewise depends on whether the vulnerable service is present and reachable in a given environment. So service inventory and reachability matter alongside exploit status when setting patch priority.

    A SharePoint chain closes

    August also completes a two-part SharePoint fix that started in July.

    Rapid7 Labs reported an exploit chain to Microsoft on May 18 that combined an authentication bypass with a separate code execution vulnerability to reach unauthenticated RCE against on-premises SharePoint. Microsoft confirmed two days later that it planned to split the remediation across the July and August update cycles.

    July fixed the first half, CVE-2026-55040, a Critical authentication bypass scored at 9.1. Rapid7 found that the flaw lets a remote unauthenticated attacker assume the identity of a SharePoint site user or administrator if the attacker knows the identity to impersonate. August supplies the fix for the RCE component, identified as CVE-2026-63520.

    The distinction matters: CVE-2026-63520 is the code execution half of the chain, not by itself the unauthenticated condition. Chaining the RCE with CVE-2026-55040 is what produced Rapid7’s unauthenticated RCE.

    Rapid7 says patching CVE-2026-55040 breaks the demonstrated chain, so once the July fix was applied, that route was already closed; the August update now closes the RCE component as well.

    Put CVE-2026-68820 at the top for Windows systems where an attacker already has code running and could use the flaw to reach SYSTEM. Prioritize exposed DNS, WDS, QUIC, and HPC services behind it, then confirm on-premises SharePoint farms have the July authentication-bypass fix and the August RCE fix.

    active attack driver flaws including Microsoft Patches Windows ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

    Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

    MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

    Fortra Patches Critical Vulnerabilities in BoKS

    Microsoft AI Releases MAI-Transcribe-2-Streaming: #1 Real-Time Speech-to-Text Model on Artificial Analysis

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News

    October 3, 2026

    Surfshark Promo Codes: 87% Off | October 2026

    October 3, 2026

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    October 3, 2026

    Chainalysis Used AI to Trace the $387M Bitget Hack Back to North Korea

    October 3, 2026
    Latest Posts

    Google’s top hacker hunter explains why hacking groups get codenames

    August 8, 2026

    Nicola Sturgeon ‘has not spoken to’ estranged husband, Peter Murrell, since he was jailed | Nicola Sturgeon

    August 8, 2026

    Amid Abuse Claims Against Max Miller, This Democrat Thinks He Can Win His Seat

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Remains of Bulgaria’s Czar Samuel return ‘home’ after 1,000 years | History News

    October 3, 2026

    Surfshark Promo Codes: 87% Off | October 2026

    October 3, 2026

    ShinyHunters hacker reportedly detained in Jordan, aiding FBI

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.