Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered safety fixes for 400+ vulnerabilities, together with one which has been exploited in zero-day assaults (CVE-2026-68820) and three that have been publicly disclosed previous to the discharge of the patches.

August 2026 Patch Tuesday CVE-2026-68820

Vulnerabilities of be aware

CVE-2026-68820 is a use-after-free flaw that impacts the Home windows Ancillary Operate Driver for WinSock (AFD.sys) and permits a low-privileged native attacker to raise privileges to SYSTEM.

“A regionally authenticated attacker may run a specifically crafted utility on an affected system to set off a race situation,” Microsoft explained. “Consumer interplay just isn’t required.”

Examine Level researchers reported that the vulnerability has been exploited by North Korean attackers to deploy a kernel-mode rootkit in a brand new wave of the Operation Dream Job campaign.

The three publicly disclosed vulnerabilities are:

CVE-2026-62832, a vulnerability within the Home windows Consumer Profile Service which will permit an authenticated attacker to realize Admin privileges by operating a specifically crafted utility.

“That is the flaw behind ‘LegacyHive,’ the unpatched proof-of-concept launched by researcher Nightmare-Eclipse simply hours after July’s Patch Tuesday,” commented Chris Goettl, VP of Product Administration for safety merchandise at Ivanti.

“This vulnerability lets a regular person coerce the Consumer Profile Service into loading one other person’s registry hive – together with an administrator’s – to achieve unauthorized entry to that person’s Courses registry knowledge.”

CVE-2026-72971 impacts the Home windows Container Isolation FS Filter Driver (unionfs.sys), which can permit authenticated attackers to tamper with a weak system. (This one solely affectes Home windows 11 variations for ARM64-based Methods.)

Crowdstrike flagged a 3rd vulnerability that was publicly disclosed earlier than the patch was made accessible: CVE-2026-62737, a elevation of privilege vulnerability affecting the Home windows kernel

“Whereas not formally acknowledged by Microsoft as publicly disclosed, a Chinese language-language weblog was revealed on August 9, 2026, describing a proof-of-concept exploit that may trigger a system crash,” the corporate noted.

Different vulnerabilities of be aware mounted this month embody:

CVE-2026-62815, a important Microsoft QUIC vulnerability that may be exploited by unauthenticated attackers by sending a specifically crafted packet to an affected service over the community. “Profitable exploitation may permit the attacker to execute code on the goal system. No authentication or person interplay is required,” Microsoft says.

CVE-2026-62878, a stack-based buffer overflow vulnerability in Home windows DNS that may result in distant code execution. This one will also be simply, reliably and remotely exploited by unauthenticated attackers.

CVE-2026-63520, in Microsoft Sharepoint, discovered by Rapid7 researchers. It may be used along side CVE-2026-55040, a previously patched Sharepoint flaw, to realize unauthenticated distant code execution in opposition to a weak server.

A Microsoft Defender patch-bypass

In associated information, the safety researcher who goes by “Nightmare Eclipse” released a proof-of-concept (PoC) exploit that ostensibly bypasses the patch for CVE-2026-50656, the “RoguePlanet” Microsoft Defender vulnerability the corporate pushed out in July 2026.

Dubbed “ShieldBreak” by the researcher, the vulnerability professedly impacts Home windows 11, 10 and Home windows Server 2025. Vulnerability analyst Will Dormann confirmed that the PoC exploit works if Defender is enabled.

Don’t rush and check patches

“This quantity of updates certainly appears to be the brand new regular – no less than for now. What’s fascinating is that, whereas there may be an explosion of bugs being reported (and glued), there was no equal improve within the variety of bugs being actively exploited, no less than as 0-days,” says Dustin Childs, head of risk consciousness at TrendAI’s Zero Day Initiative.

He additionally identified that Microsoft itemizing actively exploited bugs as “Unproven” or downplaying working Pwn2Own exploits could pressure safety groups to carry out impartial danger triage.

Ivanti’s Goettl says that the patches must be triaged to establish CVEs that require quick consideration and that organizations must do not forget that CVEs with excessive CVSS scores however which aren’t exploited or should not in internet-facing methods may be dealt with in a second spherical of patching.

Tyler Reguly, Affiliate Director, Safety R&D at Fortra, says that regardless of the newest mega-updates, IT admins and safety groups ought to maintain calm and never rush updates: “You want to just be sure you are rolling out secure updates that won’t negatively influence your methods.”

His recommendation for CISOs is to speak to their groups about how they’re shifting or modifying their workflows to higher accommodate this patching shift, and help them by enabling the adjustments they wish to see made.

Subscribe to our breaking information e-mail alert to by no means miss out on the newest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *