Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    August 12, 2026

    Ripple news: XRP bridge drained after software mistook fake deposits for real ones

    August 12, 2026

    British driver who broke sound barrier sets new speed record

    August 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
    • Ripple news: XRP bridge drained after software mistook fake deposits for real ones
    • British driver who broke sound barrier sets new speed record
    • Ceuta showed just how easy it is to divide Europe | Paul Taylor
    • Making sense of claim Massachusetts legalized ‘abortion until birth’
    • Middle East live: US military strikes ship violating blockade of Iranian ports
    • Farage vs. Binface: Inside the Clacton by-election circus – POLITICO
    • British man with dementia told to leave Sweden after losing migration case | Sweden
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 12, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 11, 2026Vulnerability / Windows Security

    Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.

    The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.

    The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month’s release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft has not publicly attributed the exploitation. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign.

    Four other flaws in the release need nothing at all from the victim: no account, no password, no click. They affect Windows DNS Server, Windows Deployment Services, Microsoft’s implementation of the QUIC transport protocol, and High Performance Computing (HPC) Pack, and each carries a CVSS score of 9.8. None was flagged as exploited when the updates shipped.

    Cybersecurity

    Counting independently, the Zero Day Initiative puts the release at 398 new CVEs, 62 of them rated Critical. The count shows the size of the release; exploit status and reach decide the patch order.

    The release also closes the RCE half of a SharePoint chain whose authentication bypass was fixed in July. On-premises SharePoint farms should have both updates installed.

    Check Point Research said CVE-2026-68820 is a use-after-free in afd.sys, the Ancillary Function Driver for WinSock and a kernel-side component of Windows networking.

    The bug is privilege escalation: an attacker needs code running on the machine first, then can use it to reach SYSTEM. Microsoft flags it as actively exploited, which puts it ahead of the four 9.8 server RCEs here despite the lower score.

    Nothing required from the victim

    The four unauthenticated remote code execution flaws are the ones to queue behind the exploited driver bug because they can give an attacker code on a server without first needing an account or a user action.

    • CVE-2026-62878, Windows DNS Server. A stack-based buffer overflow reachable remotely with no authentication and no user interaction. The Zero Day Initiative describes the condition as wormable despite Microsoft rating exploitation as less likely. ZDI’s “wormable” label describes the technical condition; it does not establish that a worm exists.
    • CVE-2026-62893, Windows Deployment Services. A remote flaw reachable through the service’s TFTP handling without authentication or user interaction.
    • CVE-2026-62815, Microsoft QUIC. A remote, unauthenticated code execution flaw requiring no user interaction.
    • CVE-2026-59124, HPC Pack. It carries the same 9.8 score but is rated Important rather than Critical because HPC Pack is not installed by default. Microsoft rates exploitation as more likely.
    Cybersecurity

    HPC Pack is not installed by default, and the practical priority of the other three likewise depends on whether the vulnerable service is present and reachable in a given environment. So service inventory and reachability matter alongside exploit status when setting patch priority.

    A SharePoint chain closes

    August also completes a two-part SharePoint fix that started in July.

    Rapid7 Labs reported an exploit chain to Microsoft on May 18 that combined an authentication bypass with a separate code execution vulnerability to reach unauthenticated RCE against on-premises SharePoint. Microsoft confirmed two days later that it planned to split the remediation across the July and August update cycles.

    July fixed the first half, CVE-2026-55040, a Critical authentication bypass scored at 9.1. Rapid7 found that the flaw lets a remote unauthenticated attacker assume the identity of a SharePoint site user or administrator if the attacker knows the identity to impersonate. August supplies the fix for the RCE component, identified as CVE-2026-63520.

    The distinction matters: CVE-2026-63520 is the code execution half of the chain, not by itself the unauthenticated condition. Chaining the RCE with CVE-2026-55040 is what produced Rapid7’s unauthenticated RCE.

    Rapid7 says patching CVE-2026-55040 breaks the demonstrated chain, so once the July fix was applied, that route was already closed; the August update now closes the RCE component as well.

    Put CVE-2026-68820 at the top for Windows systems where an attacker already has code running and could use the flaw to reach SYSTEM. Prioritize exposed DNS, WDS, QUIC, and HPC services behind it, then confirm on-premises SharePoint farms have the July authentication-bypass fix and the August RCE fix.

    active attack driver flaws including Microsoft Patches Windows ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    British driver who broke sound barrier sets new speed record

    Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse

    Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws

    Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

    DeadLock ransomware uses blockchain to resist infrastructure takedown

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    August 12, 2026

    Ripple news: XRP bridge drained after software mistook fake deposits for real ones

    August 12, 2026

    British driver who broke sound barrier sets new speed record

    August 12, 2026

    Ceuta showed just how easy it is to divide Europe | Paul Taylor

    August 12, 2026
    Latest Posts

    I grew up near Andy Burnham. This is what shaped our new PM | Andy Burnham

    July 25, 2026

    The Economic Philosophy of Britain’s Andy Burnham

    July 25, 2026

    Samsung Wallet Will Add Stablecoin Support, Including USDC

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    August 12, 2026

    Ripple news: XRP bridge drained after software mistook fake deposits for real ones

    August 12, 2026

    British driver who broke sound barrier sets new speed record

    August 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.