August Patch Tuesday Brings 398 CVEs as Microsoft Tackles Exploited Windows Flaw

Share

- Advertisement -
  • CVE 2026 68820 is already being exploited and can help an attacker move from existing code execution to SYSTEM privileges.
  • Four 9.8 rated vulnerabilities affect DNS Server, Windows Deployment Services, QUIC and HPC Pack, with no authentication or user interaction required.
  • The August SharePoint update fixes the RCE component of an attack chain whose authentication bypass was patched in July.
  • Patch priority should be based on exploitation, service exposure and whether vulnerable software is actually deployed, not simply on CVSS scores.

Microsoft’s August 2026 security release includes a Windows kernel vulnerability that is already being exploited in attacks, making it the most urgent issue for organizations to address.

The flaw, tracked as CVE 2026 68820, carries a CVSS score of 7.0 and affects afd.sys, the Ancillary Function Driver responsible for parts of Windows networking and socket operations. Unlike a typical remote attack, an attacker needs to have code running on the affected computer before exploiting the vulnerability. Once that foothold exists, however, the flaw can potentially be used to elevate privileges and gain SYSTEM level access.

Microsoft has confirmed that the vulnerability is being exploited in the wild. It has not publicly linked the activity to a specific threat actor, although Check Point Research has attributed exploitation to Lazarus as part of its Operation Dream Job campaign.

The vulnerability is understood to involve a use after free condition that can be triggered through a race condition in the networking driver. In practical terms, successful exploitation could allow an attacker who has already compromised a Windows machine to increase their privileges significantly.

That makes CVE 2026 68820 the first patch to prioritize on affected Windows systems.

The relatively modest CVSS score should not distract from the more important detail: attackers are already using the flaw. For defenders, confirmed exploitation is generally a stronger warning sign than the severity score alone.

- Advertisement -

Four critical server flaws need attention next

Microsoft’s August release also addresses four vulnerabilities with CVSS scores of 9.8. None was known to be under active exploitation when the patches were released, but their combination of remote reachability and lack of authentication makes them important targets for administrators.

The first is CVE 2026 62878, a vulnerability in Windows DNS Server. It is described as a stack based buffer overflow that can be reached remotely without authentication or user interaction. The Zero Day Initiative has also described the technical characteristics as potentially wormable, although that does not mean a worm is currently spreading through networks.

CVE 2026 62893 affects Windows Deployment Services. The vulnerability can be reached remotely through the service’s TFTP handling and does not require an attacker to authenticate or persuade a user to do anything.

Next is CVE 2026 62815, which affects Microsoft’s implementation of the QUIC transport protocol. It is another remote code execution vulnerability that can be exploited without authentication or user interaction.

The fourth is CVE 2026 59124, affecting Microsoft HPC Pack. It also has a 9.8 CVSS score and can be remotely exploited without authentication or user interaction. Microsoft rates the vulnerability as Important rather than Critical because HPC Pack is not installed by default. Its exploitation is nevertheless considered more likely.

For administrators, the practical risk depends heavily on which services are actually deployed and exposed. A vulnerability in a service that is not installed is obviously less pressing than one sitting on an internet facing server.

- Advertisement -

That means patching should go hand in hand with checking service inventories, network exposure and unnecessary installations.

SharePoint fix completes a two part attack chain

Microsoft’s August updates also finish the remediation of a serious SharePoint attack chain that began with a security fix released in July.

Rapid7 Labs reported the chain to Microsoft in May. Researchers demonstrated how an authentication bypass could be combined with a separate remote code execution vulnerability to achieve unauthenticated code execution against on premises SharePoint installations.

The first part, CVE 2026 55040, was patched in July. It was a Critical vulnerability with a CVSS score of 9.1 and could allow a remote unauthenticated attacker to assume the identity of a SharePoint user or administrator if the attacker knew which identity to impersonate.

The August update addresses the second part, CVE 2026 63520, which provides the code execution component of the chain.

It is an important distinction. CVE 2026 63520 is not, on its own, the same unauthenticated attack path demonstrated by Rapid7. The dangerous chain relied on combining the August vulnerability with the authentication bypass addressed in July.

- Advertisement -

Rapid7 has said that applying the July fix already breaks the demonstrated attack chain. Installing the August update is still important because it removes the underlying code execution vulnerability and closes the remaining component of the attack path.

Organizations running on premises SharePoint should therefore verify that both months of security updates have been installed.

How administrators should prioritize the August fixes

The August release is large. The Zero Day Initiative counts 398 newly addressed CVEs, including 62 rated Critical. That number is useful for understanding the scale of the release, but it should not be used as the only guide for deciding what gets patched first.

A more practical order starts with vulnerabilities that are already being exploited, followed by flaws that are remotely reachable without authentication, particularly when the affected services are exposed to untrusted networks.

For Windows machines where attackers could already have code execution, CVE 2026 68820 should be treated as the immediate priority because exploitation has been confirmed.

Administrators should then look at DNS Server, Windows Deployment Services and QUIC systems that are exposed or accessible from potentially hostile networks. HPC Pack deserves attention where it is installed, particularly because Microsoft considers exploitation more likely.

Finally, organizations running on premises SharePoint should confirm that both the July authentication bypass fix and the August remote code execution fix are in place.

Follow TechBSB For More Updates

- Advertisement -
Emily Parker
Emily Parker
Emily Parker is a seasoned tech consultant with a proven track record of delivering innovative solutions to clients across various industries. With a deep understanding of emerging technologies and their practical applications, Emily excels in guiding businesses through digital transformation initiatives. Her expertise lies in leveraging data analytics, cloud computing, and cybersecurity to optimize processes, drive efficiency, and enhance overall business performance. Known for her strategic vision and collaborative approach, Emily works closely with stakeholders to identify opportunities and implement tailored solutions that meet the unique needs of each organization. As a trusted advisor, she is committed to staying ahead of industry trends and empowering clients to embrace technological advancements for sustainable growth.

Read More

Trending Now