Tech News

August 2026 Patch Tuesday: 421 Flaws Fixed, Including a Lazarus-Exploited Zero-Day

421 vulnerabilities fixed, including 3 zero-day flaws. August 2026 Patch Tuesday is smaller than July’s monster release, but it remains one of the largest Patch Tuesday updates Microsoft has ever published. Most notably, one of the zero-days patched by Microsoft is already being exploited by the North Korean Lazarus group. Here’s what you need to know.

Despite the 570 vulnerabilities fixed in July, I wasn’t expecting any slowdown. In fact, Microsoft had already warned us that there would be many flaws in the months ahead, notably thanks to discoveries made with the help of AI. On Tuesday, August 11, 2026, Microsoft unveiled August 2026 Patch Tuesday, with fixes for 421 vulnerabilities. That’s twice as many as in June, confirming Microsoft’s new pace of releases.

This Patch Tuesday addresses a total of 62 critical security flaws and 110 remote code execution vulnerabilities. By product, Windows alone accounts for 236 security flaws according to the count shown on the Microsoft website. Next comes Office with 98 flaws and SharePoint Server with no fewer than 30 patched vulnerabilities. I’d also like to draw your attention to these vulnerabilities:

  • DNS Server: several critical remote code execution flaws, including CVE-2026-62878 with a CVSS score of 9.8 out of 10.
  • Windows Deployment Services (WDS): CVE-2026-62893 affects the embedded TFTP server in WDS and is also rated CVSS 9.8.
  • Microsoft - QUIC: CVE-2026-62815 lies in Windows’ QUIC implementation and allows remote code execution via a network packet. It is also a critical flaw rated CVSS 9.8.
  • iSCSI Target Service: CVE-2026-65791 allows remote code execution, with a CVSS score of 9.8.
  • DHCP Server: a remote code execution flaw in the Windows Server DHCP Server (CVE-2026-62823), while noting that this role is also affected by other vulnerabilities.
  • AD CS: CVE-2026-62818 affects Active Directory Certificate Services and allows remote code execution.

CVE-2026-68820: the zero-day Lazarus had already been exploiting since July

For August 2026 Patch Tuesday, Microsoft patched CVE-2026-68820, a use-after-free flaw in the afd.sys driver. This refers to what Microsoft calls the Ancillary Function Driver for WinSock, the kernel component that serves as the foundation for the Windows Sockets API.

On its website, Microsoft explains that this is a privilege escalation vulnerability on Windows: "A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. No user interaction is required."

More importantly, this is already an exploited zero-day! In fact, this vulnerability was discovered by Moshe Marelus and David Driker from Check Point. Following Microsoft’s disclosure, the company published a report detailing how this flaw was exploited by Lazarus, the North Korea-linked hacking group.

In its report, Check Point describes a cyberattack and states: "During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit." - In addition, a FudModule sample analyzed by researchers was compiled on July 7, 2026, suggesting several weeks of exploitation of this flaw by the Lazarus group before this security patch was released.

Check Point mentions targets in Europe, notably in France and Germany. Exploiting CVE-2026-68820 is only one step in the full attack chain. Once initial access is obtained, CVE-2026-68820 is used to gain SYSTEM privileges, after which FudModule is deployed.

Does this scenario sound familiar? Back in August 2024, Lazarus exploited another zero-day in this same AFD.sys driver (CVE-2024-38193) to deploy an earlier version of FudModule. This time, history repeats itself with another flaw in the same driver. Finally, note that CISA added CVE-2026-68820 to its KEV catalog on August 11, 2026.

Two disclosed zero-days, and Nightmare Eclipse still at work

The other two zero-day flaws patched by Microsoft this month were disclosed before the fix was released, but they are not being exploited.

CVE-2026-62832, privilege escalation in the User Profile Service

Rated CVSS 7.8 out of 10, CVE-2026-62832 is located in the User Profile Service. Microsoft explains: "A authenticated attacker with the credentials of another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges."

Microsoft credits the discovery to an anonymous researcher. However, the description of this flaw should remind you of one of my previous articles: the description matches LegacyHive, the zero-day published by Nightmare Eclipse just hours after July’s Patch Tuesday. It is now patched.

CVE-2026-72971, tampering in the container isolation filter driver

This vulnerability is located in unionfs.sys, the component that provides file system isolation for containerized workloads on Windows. It could allow an attacker to overwrite certain files. It is worth noting that this flaw is specific to Windows 11 26H1, the version intended for new devices powered by ARM processors (such as the Qualcomm Snapdragon X2 lineup). In other words, it does not affect most Windows 11 machines.

And the Microsoft vs. Nightmare Eclipse saga? It continues. The researcher disclosed another flaw dubbed ShieldBreak, which I’ll discuss in a future article.

SharePoint: the second half of an execution chain

To wrap up, let’s talk about SharePoint Server. Among the 30 vulnerabilities fixed in this product, CVE-2026-63520 is worth a closer look. It was discovered by Rapid7, and in a report, Rapid7 explains that it is the second link in an exploitation chain. By combining two vulnerabilities, a remote unauthenticated attacker can execute code on a vulnerable SharePoint server. The first security flaw, CVE-2026-55040 (a PoC is now available), was fixed during July’s Patch Tuesday.

Patches are available for SharePoint Server Subscription Edition, 2019, and 2016. After the wave of compromises targeting on-premises SharePoint servers in recent months, including the zero-day exploited in July, do not overlook this new patch.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.