Microsoft Patches 421 CVEs, Zero-Day Exploit in Windows
TL;DR. Microsoft issued patches for 421 CVEs, including a critical zero-day vulnerability actively exploited in the Windows kernel-mode driver. - The exploited flaw, CVE-2026-68820, is a use-after-free issue in afd.sys allowing attackers to gain SYSTEM privileges. - Attackers could leverage a specially crafted application to trigger a race condition without user interaction. - This zero-day marks another instance of afd.sys exploitation, previously linked to nation-state threat actors like the Lazarus group.
- Microsoft released patches for 421 Common Vulnerabilities and Exposures (CVEs) in August 2026.
- A critical zero-day vulnerability (CVE-2026-68820) in the Windows kernel-mode driver (afd.sys) was exploited for privilege escalation.
- The flaw allows local authenticated attackers to gain SYSTEM privileges without user interaction by exploiting a race condition.
- This vulnerability is part of a pattern of afd.sys exploits, with some previously attributed to state-sponsored groups.
Sources
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day — securityweek.com
- thehackernews.com — thehackernews.com