Microsoft Patches 421 CVEs, Zero-Day Exploit in Windows

TL;DR. Microsoft issued patches for 421 CVEs, including a critical zero-day vulnerability actively exploited in the Windows kernel-mode driver. - The exploited flaw, CVE-2026-68820, is a use-after-free issue in afd.sys allowing attackers to gain SYSTEM privileges. - Attackers could leverage a specially crafted application to trigger a race condition without user interaction. - This zero-day marks another instance of afd.sys exploitation, previously linked to nation-state threat actors like the Lazarus group.

Sources

Back to QLANKR News