BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Aug Patch Tuesday: Zero-day exploited, 4 critical RCEs

Microsoft fixes actively exploited zero-day plus four critical RCE flaws

  • Microsoft’s August 2026 Patch Tuesday fixes an actively exploited zero-day (CVE-2026-68820) in the Windows kernel driver, used by Lazarus Group in Operation Dream Job.
  • Four additional unauthenticated remote code execution flaws (CVSS 9.8) affect Windows DNS Server, Deployment Services, QUIC, and HPC Pack, but none are yet exploited.
  • A two-part SharePoint exploit chain is now fully closed, combining an authentication bypass fixed in July with an RCE flaw patched this month.

Microsoft released its monthly security updates on Tuesday, closing a zero-day vulnerability in a core Windows kernel driver that attackers are already exploiting. The bug, tracked as CVE-2026-68820 (CVSS 7.0), resides in the Ancillary Function Driver for WinSock and allows an attacker with code already on a machine to escalate privileges to SYSTEM.

- Advertisement -

Check Point Research attributed the exploitation to the Lazarus Group, which used the flaw in its Operation Dream Job campaign, according to their report. Microsoft flags only this vulnerability as under active exploitation, making it the top patch priority despite its lower score.

Meanwhile, four other flaws (each CVSS 9.8) require no user action, no account, and no password, affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack. The Zero Day Initiative notes that the DNS Server bug is wormable in technical terms, though Microsoft rates exploitation as less likely.

Consequently, administrators should prioritize the exploited driver flaw first, then the unauthenticated RCEs based on service exposure. The August release also completes a two-part SharePoint fix: the authentication bypass (CVE-2026-55040) was patched in July, and now the code execution component (CVE-2026-63520) is closed.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Circle Launches Bitcoin-Backed Borrowing for Institutions Via USDC

Circle launched a Bitcoin-backed borrowing service for institutional clients, allowing eligible Circle Mint customers...

TASK#STOMP Campaign Uses PowerShell Backdoor to Steal Data

Security researchers have uncovered a new campaign dubbed TASK#STOMP that deploys a PowerShell...

Bitmine 98% to 5% ETH goal after $74M buy

Bitmine bought 27,562 ETH, bringing its total holdings to 5,983,940 ETH ($16.1 billion), or...

Einride, Nvidia Partner for Next-Gen Autonomous Trucks

Einride will build its next-gen autonomous system on NVIDIA’s Drive Hyperion platform.The company expects...

Justin Sun’s $66M Math Prize Lacks Proof of Funds

Justin Sun announced the Justin Sun Prize, offering $1 million for solving 66 mathematical...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading