Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Clear Sky Humidity: 70%
Wind: 2.65 M/S

Microsoft Closes 398 Security Gaps, Including a Windows Driver Zero-Day Targeted by Attackers

Microsoft Closes 398 Security Gaps, Including a Windows Driver Zero-Day Targeted by Attackers

Microsoft's August Patch Tuesday release addresses 398 security vulnerabilities across its product portfolio, including a Windows kernel zero-day that is already being exploited in real-world attacks.

At the top of the priority list is CVE-2026-68820, a privilege escalation vulnerability affecting a core Windows networking component. The flaw resides in afd.sys (Ancillary Function Driver for WinSock), a kernel-level driver responsible for managing network socket operations. An attacker who already has code execution on a compromised system can exploit the flaw to elevate privileges to SYSTEM, Windows' highest privilege level.

Rated 7.0 on the CVSS scale, CVE-2026-68820 is the only vulnerability in this month's security updates that Microsoft has confirmed is under active attack. Successful exploitation requires triggering a race condition within the vulnerable driver. While Microsoft has not publicly attributed the attacks, researchers at Check Point Research have linked the vulnerability to the Lazarus Group's Operation Dream Job campaign.

Despite its lower severity score, the vulnerability's active exploitation status places it above several higher-rated flaws when determining patching priorities.

Four Critical Remote Code Execution Flaws

Microsoft also patched four highly severe vulnerabilities with CVSS scores of 9.8. These flaws require no authentication, no user interaction, and no existing account, making them particularly concerning in exposed environments.

The affected components include:

  • CVE-2026-62878 – Windows DNS Server
  • CVE-2026-62893 – Windows Deployment Services (WDS)
  • CVE-2026-62815 – Microsoft QUIC
  • CVE-2026-59124 – High Performance Computing (HPC) Pack

Among these, CVE-2026-62878 is a stack-based buffer overflow in Windows DNS Server that can be exploited remotely. The Zero Day Initiative (ZDI) described the flaw as potentially wormable, meaning it possesses characteristics that could enable self-propagating attacks, although no worm has been observed in the wild.

The WDS vulnerability impacts the service's handling of TFTP requests, while the QUIC flaw enables unauthenticated remote code execution through Microsoft's implementation of the transport protocol. The HPC Pack vulnerability also allows remote code execution but is classified as Important rather than Critical because the software is not installed by default. Microsoft nevertheless considers exploitation of the HPC flaw more likely.

Organizations should evaluate the exposure of these services within their environments. Vulnerabilities affecting publicly accessible or internet-facing systems should be prioritized immediately after the actively exploited Windows zero-day.

Nearly 400 Vulnerabilities Addressed

According to the Zero Day Initiative, Microsoft's August release contains 398 newly assigned CVEs, including 62 vulnerabilities rated Critical. While the volume of fixes highlights the breadth of Microsoft's update cycle, patching decisions should be driven by exploitability, exposure, and operational risk rather than vulnerability count alone.

SharePoint Exploit Chain Fully Remediated

Microsoft also completed remediation of a SharePoint exploit chain that was first addressed in July.

The issue was originally reported by Rapid7 Labs, which identified an attack chain combining an authentication bypass vulnerability with a remote code execution flaw to achieve unauthenticated remote code execution against on-premises SharePoint deployments.

The first component, CVE-2026-55040, was patched in July. The authentication bypass vulnerability, rated 9.1 CVSS, allowed attackers to impersonate legitimate SharePoint users or administrators if the target identity was known.

This month's updates address the second stage of the chain, CVE-2026-63520, the remote code execution component. Although either flaw alone presents risk, combining the two enabled attackers to achieve full unauthenticated remote code execution.

Rapid7 noted that organizations that installed July's authentication bypass update had already disrupted the demonstrated attack path. The August update now eliminates the remaining RCE component, completing Microsoft's remediation efforts.

Recommended Patch Priorities

Organizations should prioritize updates in the following order:

  1. CVE-2026-68820 (Windows afd.sys zero-day) due to confirmed active exploitation.
  2. Internet-facing DNS Server, WDS, QUIC, and HPC Pack systems affected by the four critical unauthenticated RCE vulnerabilities.
  3. On-premises SharePoint environments, ensuring both the July authentication bypass fix (CVE-2026-55040) and the August RCE fix (CVE-2026-63520) are installed.

Given the combination of active exploitation, multiple high-severity server-side vulnerabilities, and the completion of a significant SharePoint attack chain, organizations should treat this month's Patch Tuesday release as a high-priority deployment cycle.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.