- Microsoft’s August 2026 Patch Tuesday fixes an actively exploited zero-day (CVE-2026-68820) in the Windows kernel driver, used by Lazarus Group in Operation Dream Job.
- Four additional unauthenticated remote code execution flaws (CVSS 9.8) affect Windows DNS Server, Deployment Services, QUIC, and HPC Pack, but none are yet exploited.
- A two-part SharePoint exploit chain is now fully closed, combining an authentication bypass fixed in July with an RCE flaw patched this month.
Microsoft released its monthly security updates on Tuesday, closing a zero-day vulnerability in a core Windows kernel driver that attackers are already exploiting. The bug, tracked as CVE-2026-68820 (CVSS 7.0), resides in the Ancillary Function Driver for WinSock and allows an attacker with code already on a machine to escalate privileges to SYSTEM.
Check Point Research attributed the exploitation to the Lazarus Group, which used the flaw in its Operation Dream Job campaign, according to their report. Microsoft flags only this vulnerability as under active exploitation, making it the top patch priority despite its lower score.
Meanwhile, four other flaws (each CVSS 9.8) require no user action, no account, and no password, affecting Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack. The Zero Day Initiative notes that the DNS Server bug is wormable in technical terms, though Microsoft rates exploitation as less likely.
Consequently, administrators should prioritize the exploited driver flaw first, then the unauthenticated RCEs based on service exposure. The August release also completes a two-part SharePoint fix: the authentication bypass (CVE-2026-55040) was patched in July, and now the code execution component (CVE-2026-63520) is closed.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
