CVE-2026-68820
published 2026-08-11CVE-2026-68820: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
PriorityP184high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-08-25
Exploited in the wild
EPSS
6.18%
93.0th percentile
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_10_1809 | < 10.0.17763.9115 | 10.0.17763.9115 |
| microsoft | windows_10_21h2 | < 10.0.19044.7663 | 10.0.19044.7663 |
| microsoft | windows_10_22h2 | < 10.0.19045.7663 | 10.0.19045.7663 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.9121 | 10.0.17763.9121 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.7663 | 10.0.19044.7663 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.7663 | 10.0.19045.7663 |
| microsoft | windows_11_23h2 | < 10.0.22631.7517 | 10.0.22631.7517 |
| microsoft | windows_11_24h2 | < 10.0.26100.9106 | 10.0.26100.9106 |
| microsoft | windows_11_25h2 | < 10.0.26200.9106 | 10.0.26200.9106 |
| microsoft | windows_11_26h1 | < 10.0.28000.2704 | 10.0.28000.2704 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.7517 | 10.0.22631.7517 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.9168 | 10.0.26100.9168 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.9168 | 10.0.26200.9168 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2704 | 10.0.28000.2704 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.26280 | 6.2.9200.26280 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.23338 | 6.3.9600.23338 |
| microsoft | windows_server_2016 | < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_server_2019 | < 10.0.17763.9115 | 10.0.17763.9115 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.9121 | 10.0.17763.9121 |
| microsoft | windows_server_2022 | < 10.0.20348.5440 | 10.0.20348.5440 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.5499 | 10.0.20348.5499 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2025 Ancillary Function Driver for WinSock use after free
vuldb·2026-08-12·CVSS 7.0
CVE-2026-68820 [HIGH] Microsoft Windows up to Server 2025 Ancillary Function Driver for WinSock use after free
A vulnerability, which was classified as very critical, has been found in Microsoft Windows. This issue affects some unknown processing of the component Ancillary Function Driver for WinSock. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-68820. The attack can only be performed from a local environment. No exploit is available.
It is suggested to install a patch to address this issue.
GHSA
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
ghsa_unreviewed·2026-08-11
CVE-2026-68820 [HIGH] CWE-416 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
VulnCheck
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
vulncheck·2026·CVSS 7.0
CVE-2026-68820 [HIGH] Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Affected: Microsoft Windows 10 Version 1607
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Aug; https://kevintel.com/CVE-2026-68820; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
CISA
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
cisa·2026-08-11·CVSS 7.0
CVE-2026-68820 [HIGH] CWE-416 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Vulnerability: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Affected: Microsoft Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherenc
No detection rules found.
No public exploits indexed.
Hackernews
Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
blogs_hackernews·2026-08-21·CVSS 10.0
CVE-2026-69836 [CRITICAL] Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution
Update: The story was updated after publication to note that the vulnerability has not been exploited.
Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment. It also noted, "this vulnerability was not exploited in the wild."
"We identified and addressed this issue with a fix and released CVE-2026-69836 for greater transparency . There are no additiona
Tenable
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
blogs_tenable·2026-08-18
CVE-2026-68820 Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
## Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.
## Key Takeaways
The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates
154 issues (16.3% of all patches) were assigned a critical severity rating
Oracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patches
## Background
On August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026 . Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-s
Qualys
CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
blogs_qualys·2026-08-18·CVSS 7.0
CVE-2026-68820 [HIGH] CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
## Table of Contents
CISA BOD 26-04 Timeline
How CVE-2026-68820 Can Be Exploited
Patch Limitation: The Need to Reboot
Our Recommendation: Deploy the Patch Now
How We Calculate Patch Reliability
Frequently Asked Questions (FAQs)
## Executive Summary
CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires affected endpoints to reboot. Qualys AI-Powered Patch Reliability
Checkpoint
17th August – Threat Intelligence Report
blogs_checkpoint·2026-08-17
CVE-2026-68820 17th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin.
TOP ATTACKS AND BREACHES
Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident.
MyDr, Poland’s primary
Hackernews
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
blogs_hackernews·2026-08-17·CVSS 9.8
CVE-2026-59310 [CRITICAL] ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones.
This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely.
So, nothing magical. Just a lot of small openings turning into bigger problems. Here’s what stood out.
## ⚡ Threat of the Week
Suspected China APT Behind Exploitation of New V
Tenable
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
blogs_tenable·2026-08-14·CVSS 9.8
CVE-2025-3248 [CRITICAL] The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
## The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.
## Key Takeaways
Taiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.
The Taiwan campaign is part of a broader seven-incident agentic AI threat cluster that also includes JADEPUFFER
Hackernews
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
blogs_hackernews·2026-08-12·CVSS 7.0
CVE-2026-68820 [HIGH] Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.
The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft ha
Hackernews
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
blogs_hackernews·2026-08-12·CVSS 7.0
CVE-2026-68820 [HIGH] Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India.
The activity, per Check Point Research, is part of Operation Dream Job , a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockhee
Hackernews
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
blogs_hackernews·2026-08-12·CVSS 7.0
CVE-2026-50656 [HIGH] ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak .
The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet .
RoguePlanet has been described as a race condition that, if successfully exploited, could grant an attacker the ability to spawn a shell with SYSTEM-level privileges, enabling them
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Tenable
Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
blogs_tenable·2026-08-11·CVSS 7.0
CVE-2026-68820 [HIGH] Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
## Microsoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
42 Critical
355 Important
1 Moderate
0 Low
Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.
Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.
This month’s update includes patches for:
.NET
.NET Core
.NET Framework
AMD Zen
Active Directory Certificate Services (AD CS)
Application Information Services
Azure Active Directory
Azure CycleCloud
Azure Monitor Agent
Azure Storage Explorer
Capability Access Management Service (camsvc)
Desktop Window M
Qualys
Microsoft Patch Tuesday, August 2026 Security Update Review
blogs_qualys·2026-08-11
CVE-2026-72971 Microsoft Patch Tuesday, August 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forAugust2026
Zero-day Vulnerabilities Patched inAugustPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inAugustPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security.
## Microsoft Patch Tuesday for August 2026
This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities.
In this month’s updates, Microsof
Checkpoint
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
blogs_checkpoint·2026-08-11·CVSS 8.8
CVE-2026-68820 [HIGH] Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Latest Publications
CPR Podcast Channel
AI Research
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 18
Android Malware 23
Artificial Intelligence 5
ChatGPT 3
Check Point Research Publications 465
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 420
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 175
Web 3.0 Security 11
Wipers 0
## Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
## Key Points
Check Point Research is tracking a long‑running campaign called Operation Dream Job , targeting organizations worldwide, wi
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Krebs
Microsoft Plugs Nearly 400 Security Holes
blogs_krebs·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Image: Shutterstock, Mallika Home Studio.
August’s overstuffed bundle of patch joy from Microsoft did not eclipse its recording breaking release of more than 570 security updates last month , but it is double June’s then-record batch of nearly 200 fixes . Microsoft has attributed the recent patch deluge to vulnerability discoveries aided by artificial intelligence, and experts roundly agree that Windows users should get used to the idea of Patch Tuesdays (the second Tuesday of each month) covering hundreds of newly discovered secur
Talos
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-08-11·CVSS 9.4
CVE-2026-68820 [CRITICAL] Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild
CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This vulnerability has a CVSS base score of 7.0.
Out of 62 "critical" vulnerabilities, 40 are remote code execution (RCE) vulnerabilities.
Microsoft considers exploitation of the following vulnerabilities more lik
Crowdstrike
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
blogs_crowdstrike
CVE-2026-68820 August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs Aug 11, 2026
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX Aug 07, 2026
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery Aug 06, 2026
Secure Agent Harness Execution: Preventing Escape Aug 04, 2026
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs Aug 11, 2026
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX Aug 07, 2026
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery Aug 06, 2026
Secure Agent Harness Execution: Preventing Escape Aug 04, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders
2026-08-11
Published
2026-08-11
Added to CISA KEV
Exploited in the wild