August 2026 Patch Tuesday: Microsoft fixes over 420 flaws

Microsoft’s August 2026 Patch Tuesday has landed as one of many 12 months’s largest safety updates, closing out 421 CVEs, together with greater than 40 rated important, based on Microsoft’s Safety Replace Information and a number of safety distributors monitoring the discharge. The replace is headlined by an actively exploited kernel driver flaw, a publicly disclosed elevation-of-privilege bug tied to a researcher lengthy at odds with Microsoft, and a SharePoint distant code execution chain flagged by Rapid7.

Lazarus Group exploits kernel driver zero-day

Essentially the most pressing repair is CVE-2026-68820, a use-after-free vulnerability within the Home windows Ancillary Perform Driver for WinSock (afd.sys), the kernel-mode driver underpinning the Home windows Sockets API. Microsoft says a regionally authenticated attacker can set off a race situation by means of a specifically crafted utility to achieve SYSTEM privileges with out person interplay. Check Point Research reported that North Korea’s Lazarus Group exploited the flaw as a part of its Operation Dream Job marketing campaign, utilizing pretend recruiter outreach and a trojanized PDF viewer to deploy Troy, a brand new backdoor, earlier than escalating privileges and putting in an up to date model of its FudModule kernel-mode rootkit. The exercise has targeted on protection, aerospace, and aviation organizations throughout Europe, India, and Brazil. CISA has added CVE-2026-68820 to its Identified Exploited Vulnerabilities catalog, with a remediation deadline of August 25.

A public feud over LegacyHive

Microsoft additionally patched CVE-2026-62832, an elevation-of-privilege flaw within the Home windows Consumer Profile Service. The bug lets an authenticated attacker who holds credentials for one more native account pressure the service to load that account’s registry hive, doubtlessly an administrator’s, granting unauthorized entry to that information and administrator rights. Microsoft credited the invention to an nameless researcher, although the technical particulars match LegacyHive, a proof of idea the pseudonymous researcher Nightmare Eclipse revealed simply hours after July’s Patch Tuesday. As a result of working exploit code had already circulated publicly, Microsoft assessed the flaw as extra prone to be exploited extra broadly.

Rapid7 completes a SharePoint RCE chain

Rounding out the discharge is CVE-2026-63520, a SharePoint Server distant code execution vulnerability rooted in unsafe .NET kind instantiation inside Enterprise Connectivity Providers. Rapid7 disclosed it alongside Microsoft because the second half of an exploit chain constructed for Pwn2Own Berlin. Paired with CVE-2026-55040, the JWT authentication bypass Rapid7 disclosed in July, the 2 flaws let an unauthenticated attacker execute code on a weak SharePoint server with the privileges of its service account with none credentials.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *