Microsoft launched its month-to-month safety updates on Tuesday, and one of many flaws it closed is already being utilized in assaults.
The bug sits in a core Home windows kernel driver that handles community socket operations. An attacker with code already operating on a machine can use it to escalate to SYSTEM. That patch goes out first.
The flaw is tracked as CVE-2026-68820 (CVSS rating: 7.0) and is the one one on this month’s launch Microsoft flags as below energetic exploitation. Exploitation relies on triggering a race situation within the driver. Microsoft has not publicly attributed the exploitation. Test Level Analysis says Lazarus used the zero-day in its Operation Dream Job marketing campaign.
4 different flaws within the launch want nothing in any respect from the sufferer: no account, no password, no click on. They have an effect on Home windows DNS Server, Home windows Deployment Providers, Microsoft’s implementation of the QUIC transport protocol, and Excessive Efficiency Computing (HPC) Pack, and every carries a CVSS rating of 9.8. None was flagged as exploited when the updates shipped.
Counting independently, the Zero Day Initiative places the discharge at 398 new CVEs, 62 of them rated Essential. The depend exhibits the dimensions of the discharge; exploit standing and attain resolve the patch order.
The discharge additionally closes the RCE half of a SharePoint chain whose authentication bypass was mounted in July. On-premises SharePoint farms ought to have each updates put in.
Check Point Research stated CVE-2026-68820 is a use-after-free in afd.sys, the Ancillary Function Driver for WinSock and a kernel-side element of Home windows networking.
The bug is privilege escalation: an attacker wants code operating on the machine first, then can use it to succeed in SYSTEM. Microsoft flags it as actively exploited, which places it forward of the 4 9.8 server RCEs right here regardless of the decrease rating.
Nothing required from the sufferer
The 4 unauthenticated distant code execution flaws are those to queue behind the exploited driver bug as a result of they can provide an attacker code on a server with out first needing an account or a consumer motion.
- CVE-2026-62878, Home windows DNS Server. A stack-based buffer overflow reachable remotely with no authentication and no consumer interplay. The Zero Day Initiative describes the situation as wormable regardless of Microsoft ranking exploitation as much less possible. ZDI’s “wormable” label describes the technical situation; it doesn’t set up {that a} worm exists.
- CVE-2026-62893, Home windows Deployment Providers. A distant flaw reachable via the service’s TFTP dealing with with out authentication or consumer interplay.
- CVE-2026-62815, Microsoft QUIC. A distant, unauthenticated code execution flaw requiring no consumer interplay.
- CVE-2026-59124, HPC Pack. It carries the identical 9.8 rating however is rated Vital quite than Essential as a result of HPC Pack just isn’t put in by default. Microsoft charges exploitation as extra possible.
HPC Pack just isn’t put in by default, and the sensible precedence of the opposite three likewise relies on whether or not the susceptible service is current and reachable in a given surroundings. So service stock and reachability matter alongside exploit standing when setting patch precedence.
A SharePoint chain closes
August additionally completes a two-part SharePoint repair that began in July.
Rapid7 Labs reported an exploit chain to Microsoft on Might 18 that mixed an authentication bypass with a separate code execution vulnerability to reach unauthenticated RCE against on-premises SharePoint. Microsoft confirmed two days later that it deliberate to separate the remediation throughout the July and August replace cycles.
July mounted the primary half, CVE-2026-55040, a Essential authentication bypass scored at 9.1. Rapid7 discovered that the flaw lets a distant unauthenticated attacker assume the id of a SharePoint website consumer or administrator if the attacker is aware of the id to impersonate. August provides the repair for the RCE element, recognized as CVE-2026-63520.
The excellence issues: CVE-2026-63520 is the code execution half of the chain, not by itself the unauthenticated situation. Chaining the RCE with CVE-2026-55040 is what produced Rapid7’s unauthenticated RCE.
Rapid7 says patching CVE-2026-55040 breaks the demonstrated chain, so as soon as the July repair was utilized, that route was already closed; the August replace now closes the RCE element as properly.
Put CVE-2026-68820 on the prime for Home windows methods the place an attacker already has code operating and will use the flaw to succeed in SYSTEM. Prioritize uncovered DNS, WDS, QUIC, and HPC companies behind it, then verify on-premises SharePoint farms have the July authentication-bypass repair and the August RCE repair.
