Microsoft has launched its August 2026 Patch Tuesday safety updates, addressing over 400 vulnerabilities throughout Home windows and different supported merchandise, together with three zero-day flaws that had been exploited or publicly disclosed earlier than fixes grew to become out there.
Probably the most pressing vulnerability is an elevation-of-privilege flaw within the Home windows Ancillary Operate Driver for WinSock, tracked as CVE-2026-68820. Microsoft confirmed that attackers had exploited the vulnerability within the wild, whereas Examine Level attributed the noticed assaults to the North Korean state-sponsored group extensively often known as Lazarus.
In accordance with Examine Level, Lazarus used the vulnerability to put in a brand new model of FudModule, a classy kernel-mode rootkit beforehand related to North Korean espionage operations. The exploitation shaped a part of a marketing campaign wherein targets had been approached with fraudulent employment alternatives earlier than malicious software program was delivered to their programs.
The August launch additionally fixes two vulnerabilities that had been publicly recognized earlier than patches grew to become out there: a Home windows Consumer Profile Service flaw matching the beforehand disclosed “LegacyHive” method and a tampering vulnerability within the Home windows Container Isolation file-system filter driver.
Though the whole is decrease than the unusually massive July Patch Tuesday release, which numerous counting methodologies positioned 600+ vulnerabilities, August stays certainly one of Microsoft’s largest month-to-month safety updates. The persevering with quantity underlines the rising operational strain on enterprise patch-management groups, significantly as Microsoft expands its use of synthetic intelligence to determine weaknesses throughout Home windows and different advanced codebases.
Extra Than 100 Distant-Code-Execution Vulnerabilities
Microsoft’s August safety launch consists of 42 vulnerabilities labeled as Vital. Of these, 37 may result in distant code execution, whereas 5 may permit an attacker to raise privileges.
The roughly 400 vulnerabilities embrace :
- 176 elevation-of-privilege flaws
- 110 remote-code-execution vulnerabilities
- 86 information-disclosure points
- 21 spoofing vulnerabilities
- 12 denial-of-service flaws
- 11 security-feature bypasses
- 4 Tampering flaws
These class figures shouldn’t essentially be handled as a easy mathematical complete. Patch Tuesday counts can differ relying on whether or not researchers embrace vulnerabilities revealed earlier within the month, browser points inherited from Chromium, cloud-service fixes and vulnerabilities that fall into multiple technical class.
The 400-flaw estimate covers the vulnerabilities Microsoft launched as a part of the August 11 Patch Tuesday cycle. It doesn’t embrace sure flaws in providers and merchandise comparable to Microsoft Azure, Microsoft Entra, Microsoft Groups, Microsoft Workplace, Energy Apps and Microsoft’s Mariner Linux distribution that had been corrected or disclosed individually earlier in August.
This distinction has turn out to be more and more necessary as Microsoft’s portfolio has expanded past conventional Home windows and Workplace software program. Many cloud vulnerabilities are mounted routinely by Microsoft and require no direct buyer motion, whereas vulnerabilities in self-hosted merchandise and Home windows endpoints usually rely on organisations testing and deploying the related updates.
For safety groups, the headline quantity is consequently much less necessary than the situation, exploitability and publicity of the affected parts. An actively exploited privilege-escalation flaw on worker workstations, for instance, could symbolize a extra fast hazard than a higher-scoring remote-code-execution flaw affecting a part that’s disabled or remoted in a specific atmosphere.
Lazarus Exploited Home windows Kernel Flaw
The very best-priority vulnerability within the August launch is CVE-2026-68820, an elevation-of-privilege vulnerability within the Home windows Ancillary Operate Driver for WinSock, generally represented by the afd.sys kernel driver.
The driving force gives kernel-level help for Home windows networking operations and acts as an interface between user-mode Winsock purposes and the underlying Home windows networking stack. As a result of it operates in kernel mode, a profitable memory-corruption exploit can permit an attacker to cross a crucial safety boundary and procure the best degree of privileges on a Home windows machine.
Microsoft described the vulnerability as a use-after-free situation. These flaws happen when software program continues to reference a area of reminiscence after it has been launched, probably permitting an attacker to govern the reused reminiscence and alter program execution.
Exploitation requires the attacker to be domestically authenticated and capable of run a specifically constructed software. The appliance triggers a race situation within the susceptible driver, after which profitable exploitation can grant SYSTEM privileges. No person interplay is required as soon as the attacker is able to execute the trojan horse.
The native nature of the vulnerability doesn’t make it a low-priority concern. Privilege-escalation bugs are generally used because the second stage of an intrusion. An attacker could initially get hold of restricted entry by way of phishing, malicious paperwork, stolen credentials, browser exploitation or compromised software program. A kernel vulnerability can then be used to flee the restrictions of the compromised account, disable safety controls, entry protected credentials and set up sturdy persistence.
Microsoft credited Examine Level researchers Moshe Marelus and David Driker with discovering and reporting CVE-2026-68820.
Faux Job Provide Led to Zero-Day Deployment
In its investigation, Examine Level related CVE-2026-68820 to a Lazarus marketing campaign constructed round fraudulent employment alternatives. Using pretend recruitment approaches is a well-established characteristic of North Korean cyber operations, significantly campaigns concentrating on software program builders, cryptocurrency corporations, defence organisations and expertise staff with entry to worthwhile programs.
In accordance with Check Point’s technical investigation, the attackers exploited CVE-2026-68820 to deploy a newly noticed model of FudModule, a kernel-mode rootkit linked to Lazarus.
The assault chain is critical as a result of it combines social engineering with a beforehand unknown kernel vulnerability. The preliminary job-themed contact provides the attackers a route to steer a goal to open a file, run a challenge or set up software program. As soon as code is operating with atypical person privileges, the Home windows flaw gives the escalation wanted to grab deeper management of the endpoint.
FudModule is designed to function at a degree the place it may possibly intervene with safety merchandise and conceal malicious exercise. Kernel-mode implants are significantly harmful as a result of they run inside one of the vital trusted layers of the working system. Relying on their capabilities, rootkits working at this degree could manipulate system buildings, cover processes, block telemetry, alter security-tool behaviour or shield different malware parts from elimination.
Using CVE-2026-68820 subsequently seems to have served a particular operational goal: turning an preliminary, lower-privileged compromise right into a extremely privileged and extra difficult-to-detect intrusion.
Microsoft’s advisory confirms that exploitation was detected however doesn’t present particulars concerning the affected organisations, the dimensions of the marketing campaign or the whole supply chain. The corporate’s restricted disclosure is typical when an investigation stays lively or when publishing extra info may expose victims and defensive strategies.
CVE-2026-68820 ought to obtain fast consideration throughout Home windows workstations, developer programs and different units on which customers can execute downloaded purposes. Organisations in sectors traditionally focused by Lazarus must also examine for proof of compromise slightly than assuming that putting in the patch will take away an current an infection.
A safety replace closes the vulnerability, but it surely doesn’t routinely evict an attacker who exploited the flaw earlier than the replace was put in.
FudModule Provides to Lazarus’ Kernel-Degree Arsenal
Lazarus is an umbrella identify used for a number of North Korean cyber models and operational clusters. The broader ecosystem has been linked to intelligence assortment, harmful assaults, cryptocurrency theft and financially motivated operations supposed to generate income for the North Korean state.
The group’s curiosity in kernel-level capabilities just isn’t new. Earlier FudModule campaigns have demonstrated a willingness to take advantage of Home windows drivers and different privileged parts to weaken endpoint protections. The deployment of an up to date rootkit by way of a real Home windows zero-day exhibits that these operators proceed to spend money on strategies that present stealth and resilience after preliminary entry.
Faux recruitment campaigns are particularly efficient towards technical professionals as a result of the malicious materials could be disguised as a coding evaluation, software program challenge, wage doc or video-interview software. The sufferer could count on to obtain information or execute code as a part of a respectable hiring course of, decreasing the chance that the exercise will initially seem suspicious.
Defenders ought to consequently look past standard electronic mail attachments. Recruitment-themed assaults could start by way of skilled networking providers, messaging platforms or developer communities earlier than shifting to electronic mail or attacker-controlled web sites.
Safety groups ought to look at uncommon little one processes launched by growth instruments, archive utilities, doc readers and messaging purposes. They need to additionally monitor for sudden driver exercise, makes an attempt to tamper with endpoint-security providers and anomalous SYSTEM-level processes showing shortly after a person runs recruitment-related materials.
LegacyHive Public Disclosure Addressed
The second zero-day mounted in August is CVE-2026-62832, an elevation-of-privilege vulnerability within the Home windows Consumer Profile Service.
Microsoft mentioned the weak point outcomes from improper hyperlink decision earlier than file entry, a category of vulnerability also known as hyperlink following. An attacker with native entry and credentials for an additional account can use a specifically constructed software to trigger the Consumer Profile Service to load one other person’s registry hive.
Profitable exploitation may permit the attacker to entry or modify knowledge belonging to the focused account and in the end get hold of administrator privileges. The assault doesn’t require interplay from the focused person whereas the exploit is operating, though some types of the method could rely on subsequent account exercise.
The technical description carefully matches the Home windows vulnerability publicly disclosed in July below the identify LegacyHive. Microsoft credited CVE-2026-62832 to an nameless researcher, whereas the general public LegacyHive proof of idea was launched by a researcher utilizing the identify Nightmare Eclipse.
LegacyHive focused the way in which the Home windows Consumer Profile Service handles registry hive information, symbolic hyperlinks and timing-sensitive file operations. The registry comprises in depth configuration info for Home windows, put in purposes and particular person person accounts. A registry hive comparable to UsrClass.dat can include software knowledge, Explorer historical past, shell configuration and different user-specific info.
Evaluation by Cyderes discovered that the publicly demonstrated method used symbolic-link manipulation and an opportunistic file lock to affect profile loading at a exact level within the operation. The proof of idea brought on the service to load a goal person’s registry hive right into a namespace accessible to the lower-privileged account.
ThreatLocker’s analysis reported that the unique public demonstration uncovered one other person’s registry knowledge and that modifications to the method may probably goal different hive information. Safety researcher Will Dormann additionally warned that manipulating a privileged person’s hive may create a path to executing instructions with administrative rights when that person subsequently signed in.
The August patch closes the hole that remained after LegacyHive was publicly demonstrated towards programs carrying the July safety updates.
As a result of working technical info had already been launched, CVE-2026-62832 deserves accelerated remedy despite the fact that Microsoft had not reported lively exploitation on the time of publication. Public proof-of-concept code considerably reduces the analysis required for different risk actors to breed or adapt an assault.
Shared workstations, leap servers, multi-user programs and machines the place directors commonly sign up alongside lower-privileged customers could face better publicity. The vulnerability additionally reinforces the significance of retaining privileged administrative exercise separate from atypical person computing.
Container Isolation Driver Vulnerability Additionally Publicly Identified
Microsoft additionally mounted CVE-2026-72971, a publicly disclosed tampering vulnerability within the Home windows Container Isolation file-system filter driver, unionfs.sys.
The driving force is concerned in presenting and managing layered file-system views utilized by Home windows container-isolation options. Microsoft attributed the vulnerability to researchers recognized as yhw and txz.
As with the Consumer Profile Service flaw, Microsoft described the underlying weak point as improper hyperlink decision earlier than file entry. This implies an authenticated native attacker might be able to manipulate file-system hyperlinks so {that a} privileged part accesses or adjustments a location aside from the one it supposed to course of.
The unique report seems to repeat some textual content related to CVE-2026-62832, together with references to loading one other person’s registry hive and gaining administrator privileges. That description belongs to the Consumer Profile Service vulnerability and shouldn’t be handled because the definitive exploitation path for the container driver flaw.
The dependable parts of Microsoft’s disclosure are that CVE-2026-72971 impacts unionfs.sys, requires an authorised native attacker and might allow file-system tampering. Microsoft had not publicly described the precise disclosure route, demonstrated assault chain or proof of in-the-wild exploitation when the August updates had been launched.
The dearth of reported exploitation shouldn’t be confused with an absence of threat. Container-isolation mechanisms exist to implement boundaries between purposes, information and host sources. A weak point within the supporting file-system layer may turn out to be extra critical if mixed with one other vulnerability that gives code execution inside a restricted atmosphere.
Organisations utilizing Home windows containers or container-based application-isolation applied sciences ought to check and deploy the related updates promptly. They need to additionally assessment host telemetry for suspicious symbolic-link creation, sudden modification of protected information and strange exercise involving container storage paths.
Patch Tuesday Volumes Proceed to Rise
August’s 400-flaw launch follows an exceptionally massive July replace that addressed roughly 570 vulnerabilities below the counting methodology utilized by a number of safety companies. Different organisations reported totally different totals as a result of Microsoft’s Safety Replace Information included extra entries, whereas some analyses excluded Chromium, cloud-only points or vulnerabilities revealed exterior the primary launch window.
The disagreement illustrates why uncooked Patch Tuesday totals require context. Completely different reviews could all be internally correct whereas measuring totally different units of vulnerabilities.
What is obvious is that Microsoft safety releases have gotten bigger. The corporate warned in Might that clients ought to count on the development to proceed as vulnerability reporting, automation and AI-assisted code evaluation increase.
Microsoft has developed a multi-model vulnerability-discovery platform often known as MDASH, which coordinates greater than 100 specialised AI brokers to analyse software program and validate potential weaknesses. The corporate mentioned the system discovered all 21 intentionally launched vulnerabilities in a non-public check driver with out producing a false constructive throughout that check. It additionally reported sturdy outcomes towards historic Microsoft vulnerabilities and the CyberGym safety benchmark.
Microsoft mentioned MDASH had already contributed to the invention of 16 vulnerabilities launched in Might, together with flaws within the Home windows networking and authentication stack. The corporate later expanded its use throughout Home windows, Azure, Hyper-V, Lively Listing, id providers and different security-sensitive parts. Microsoft’s research means that AI-assisted evaluation is permitting engineers to look at code paths at a depth and scale that might be tough to attain manually.
In a separate Microsoft Security Response Center statement, the corporate mentioned the rise was not the results of a lowered threshold for issuing safety fixes. As a substitute, Microsoft attributed the expansion to extra researcher participation, improved automation, expanded validation and better use of AI by each inner groups and exterior researchers.
Bigger Patch Tuesday releases don’t essentially imply that Microsoft software program has out of the blue turn out to be much less safe. They could as a substitute replicate a better skill to find and remediate latent vulnerabilities. Nevertheless, the outcome for purchasers is similar: extra updates have to be assessed, examined and deployed inside more and more compressed timeframes.
Enterprises Ought to Prioritise Exploitation, Publicity and Affect
Organisations ought to place CVE-2026-68820 on the prime of the August deployment queue as a result of exploitation has already been confirmed. Excessive-risk worker teams, together with builders, cryptocurrency personnel, defence contractors, researchers and executives, warrant specific consideration due to Lazarus’ documented use of focused job-offer lures.
Affected units needs to be patched as rapidly as operationally potential and reviewed for proof of earlier compromise. Endpoint detection instruments needs to be checked to make sure that their sensors are operating usually and haven’t been disabled or tampered with. The place suspicious exercise is recognized, organisations ought to isolate the machine, protect forensic proof and examine credentials used on the system.
CVE-2026-62832 ought to observe carefully as a result of technical particulars and proof-of-concept materials for LegacyHive have been public since July. Programs shared by a number of customers or used for privileged administration deserve precedence.
CVE-2026-72971 needs to be prioritised on Home windows programs supporting containers or application-isolation workloads, significantly the place untrusted or lower-trust code can execute on the identical host.
Directors should additionally determine the 42 Vital vulnerabilities related to their environments, particularly the 37 remote-code-execution points. Web-facing providers, area infrastructure, remote-access programs, developer endpoints and machines processing information from exterior sources ought to obtain heightened scrutiny.
The August launch as soon as once more exhibits that CVSS severity alone just isn’t an sufficient patching technique. Probably the most pressing flaw within the launch is necessary not merely due to its technical traits, however as a result of a succesful state-backed group has already integrated it right into a working assault chain.
As Microsoft and impartial researchers use AI to seek out vulnerabilities sooner, attackers are getting access to more and more succesful instruments for analysing updates and creating exploits. The interval between patch publication and widespread exploitation is subsequently prone to contract additional.
For defenders, the central lesson from August Patch Tuesday just isn’t merely that 400 flaws have been corrected. It’s that a kind of flaws had already turn out to be a part of an actual North Korean intrusion operation, two others had been publicly documented, and delayed patching now provides attackers an more and more slender however extremely worthwhile window of alternative.