The single most urgent patch in this release is CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) . The bug has a CVSS score of 7.0 (Important severity) and allows a locally authenticated attacker to trigger a race condition and escalate privileges to SYSTEM level
.
Attribution and campaign details: Check Point Research linked exploitation to North Korea's Lazarus Group as part of the Operation Dream Job campaign . The campaign distributed a modified PDF viewer called "SecurityPDF" to deploy a new backdoor named Troy, then exploited CVE-2026-68820 to install the FudModule kernel-mode rootkit
. Lazarus had been exploiting this flaw since early June 2026, according to The Register
. Microsoft released the patch on August 11 after Check Point's responsible disclosure
.
Two additional zero-days were publicly disclosed prior to Patch Tuesday but were not yet exploited in the wild:
The August 2026 update spanned the entire Microsoft ecosystem:
Wormable concerns: Four flaws in this release require no user interaction—affecting Windows DNS Server, Windows Deployment Services, Microsoft's QUIC transport implementation, and High Performance Computing (HPC) Pack. Each carries a CVSS score of 9.8, making them wormable priorities .
The August 2026 cumulative update for Windows 11 (KB5121003 for versions 25H2/24H2, KB5120240 for 23H2, KB5121000 for 26H1) bundles several new features alongside security fixes :
While the sheer volume of fixes can be overwhelming, security analysts emphasize that only one bug in this release—CVE-2026-68820—is confirmed under active exploitation . Tyler Reguly at Fortra advised organizations to prioritize the exploited WinSock flaw first, then move quickly on the wormable server-role vulnerabilities (CVSS 9.8) affecting DNS, Deployment Services, QUIC, and HPC Pack
. The three publicly known zero-days, while important, have not yet been observed in attacks.
CrowdStrike's analysis confirms this approach: patch the actively exploited WinSock elevation-of-privilege flaw immediately, then address the critical server-side patches before moving to the remaining Important-severity fixes .