
Microsoft Fixes 398 Flaws, Including Exploited Windows Zero-Day
Microsoft released its monthly security updates on Tuesday, closing 398 new vulnerabilities according to the Zero Day Initiative’s independent count. Of those flaws, 62 are rated Critical. The size of the release matters, but exploitation status and service exposure determine the practical patching order. The top priority is CVE-2026-68820, a vulnerability in a core Windows kernel driver. It is the only flaw in this month’s release that Microsoft flagged as under active exploitation. Although its CVSS score is 7.0, the ongoing exploitation puts it ahead of other flaws with higher severity scores. Check Point Research described the flaw as a use-after-free vulnerability in afd.sys, the Ancillary Function Driver for WinSock and a kernel-side component of Windows networking. Exploitation depends on triggering a race condition. An attacker must already have code running on the machine, after which the flaw can be used to escalate privileges to SYSTEM. Microsoft has not publicly attributed the attacks. Check Point Research, however, said the Lazarus group used the zero-day in its “Operation Dream Job” campaign. The release also fixes four unauthenticated remote code execution flaws, each carrying a CVSS score of 9.8. They require no account, password or action from the victim. The flaws affect Windows DNS Server, Windows Deployment Services, Microsoft’s implementation of the QUIC transport protocol and High Performance Computing Pack. None was flagged as actively exploited when the updates shipped. HPC Pack is not installed by default. The practical priority of all four flaws depends on whether the affected service is installed and reachable. Organizations should therefore consider service inventory and network exposure when scheduling the patches. The August release also completes a two-part fix for on-premises SharePoint farms. Rapid7 Labs reported a chain to Microsoft on May 18 that combined an authentication bypass with a separate code execution flaw. Microsoft confirmed two days later that it would split the remediation between July and August. July’s update fixed the authentication bypass, CVE-2026-55040, while August’s update fixes the code execution component, CVE-2026-63520. The two flaws together enabled unauthenticated remote code execution. Somali organizations using Windows or on-premises SharePoint can prioritize CVE-2026-68820, then exposed DNS, WDS, QUIC and HPC services, before confirming that both the July and August SharePoint updates are installed.
Read our sourcing and corrections policy



Be the first to comment on this story!