Windows 11 security update fixes actively exploited zero-day flaw

Microsoft has launched the August 2026 cumulative replace for Home windows 11, fixing 236 Home windows vulnerabilities, together with a privilege-escalation flaw that’s already being exploited in assaults.

The KB5121003 replace was launched earlier right now for Home windows 11 variations 24H2, 25H2, and 26H1, bringing methods to builds 26100.9168 and 26200.9168. It’s a part of Microsoft’s broader August Patch Tuesday launch, which addresses 421 CVEs throughout Home windows, Workplace, Alternate Server, SharePoint, Azure, Defender, and developer instruments.

Essentially the most pressing flaw mounted this month is CVE-2026-68820, an elevation-of-privilege vulnerability within the Home windows Ancillary Operate Driver for WinSock.

Microsoft says the bug is brought on by a use-after-free situation and is being actively exploited within the wild.

The vulnerability was reported by Examine Level researchers Moshe Marelus and David Driker and carries a CVSS rating of seven.0.

To use it, a domestically authenticated attacker with low privileges should run a specifically crafted utility and efficiently set off a race situation. If profitable, the attacker can acquire SYSTEM privileges with out requiring consumer interplay.

Though the flaw can’t be exploited remotely by itself, vulnerabilities of this sort are generally used after an attacker has already gained an preliminary foothold on a Home windows system.

CheckPoint has printed a detailed report about CVE-2026-68820, mentioning that it has been exploited by the North Korean risk group ‘Lazarus’ since a minimum of early July 2026, in campaigns focusing on navy organizations.

Microsoft additionally mounted CVE-2026-62832, a publicly disclosed Home windows Consumer Profile Service elevation-of-privilege vulnerability.

This flaw has a CVSS rating of seven.8 and is brought on by improper hyperlink decision earlier than file entry.

In response to Microsoft, an authenticated attacker with credentials for an additional native account might run a specifically crafted utility to load one other consumer’s registry hive.

Profitable exploitation might enable the attacker to entry or modify one other consumer’s knowledge and acquire administrator privileges.

Microsoft says CVE-2026-62832 has not been noticed in lively assaults, nevertheless it classifies exploitation as “Extra Probably.”

Microsoft additionally introduced that KB5121003 continues the rollout of alternative Safe Boot certificates to supported Home windows units.

The corporate started updating these certificates as a result of Safe Boot certificates utilized by many Home windows methods began expiring in June 2026. Microsoft says the newest replace expands the variety of eligible units that may robotically obtain the newer certificates via Home windows Replace.

The cumulative replace additionally upgrades a number of Home windows AI elements, together with Picture Search, Content material Extraction, Semantic Evaluation, and the Settings Mannequin, to model 1.2605.856.0.

It additionally consists of servicing stack replace KB5123304, which is designed to enhance the reliability of the Home windows replace course of.

Microsoft says it’s presently unaware of any recognized points with KB5121003.

Home windows 11 customers ought to set up the replace as quickly as attainable because of the lively exploitation of CVE-2026-68820.

Customers can set up the updates via Settings > Home windows Replace > Obtain & set up all.

CyberInsider

A system restart is required to finish the replace. Customers are additionally suggested to again up necessary knowledge upfront to cut back the chance of information loss if the set up encounters any points.

In the event you appreciated this text, be sure you comply with us on X/Twitter and likewise LinkedIn for extra unique content material.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *