BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Aug Patch Tuesday: Zero-day exploited, 4 critical RCEs

Microsoft fixes actively exploited zero-day plus four critical RCE flaws

  • Microsoft’s August 2026 Patch Tuesday fixes an actively exploited zero-day (CVE-2026-68820) in the Windows kernel driver, used by Lazarus Group in Operation Dream Job.
  • Four additional unauthenticated remote code execution flaws (CVSS 9.8) affect Windows DNS Server, Deployment Services, QUIC, and HPC Pack, but none are yet exploited.
  • A two-part SharePoint exploit chain is now fully closed, combining an authentication bypass fixed in July with an RCE flaw patched this month.

Microsoft released its monthly security updates on Tuesday, closing a zero-day vulnerability in a core Windows kernel driver that attackers are already exploiting. The bug, tracked as CVE-2026-68820 (CVSS 7.0), resides in the Ancillary Function Driver for WinSock and allows an attacker with code already on a machine to escalate privileges to SYSTEM.

- Advertisement -

Check Point Research attributed the exploitation to the Lazarus Group, which used the flaw in its Operation Dream Job campaign, according to their report. Microsoft flags only this vulnerability as under active exploitation, making it the top patch priority despite its lower score.

Meanwhile, four other flaws (each CVSS 9.8) require no user action, no account, and no password, affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack. The Zero Day Initiative notes that the DNS Server bug is wormable in technical terms, though Microsoft rates exploitation as less likely.

Consequently, administrators should prioritize the exploited driver flaw first, then the unauthenticated RCEs based on service exposure. The August release also completes a two-part SharePoint fix: the authentication bypass (CVE-2026-55040) was patched in July, and now the code execution component (CVE-2026-63520) is closed.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

IMF: Most tokenized stock trades happen off Wall St hours

More than half of tokenized equity trading happens outside regular U.S. market hours, and...

Coinbase BTC mortgage product gets thousands of applications

Coinbase Asset Management President Anthony Bassili said the Bitcoin mortgage down payment product has...

Zcash to deploy post-quantum signatures by January

Zakura expects post-quantum signature opcodes to land in ZCash in January, enabling hash-based signatures...

Musk: Starlink must be affordable in price-sensitive India

Elon Musk says Starlink must offer affordable pricing to compete in India's cheap data...

Coldcard investigating phishing link on X

A phishing link was posted on the official X account of Bitcoin hardware wallet...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading