Microsoft Fixes Critical Zero-Day Bug and Wormable DNS Flaw in August Patch Tuesday Updates
Microsoft released its Patch Tuesday security updates for August 2026, covering 398 new CVEs across various components. Sixty-two of these are rated Critical.
The most pressing issues include a zero-day bug and a wormable DNS flaw that enables remote code execution. The zero-day bug is CVE-2026-68820, a use-after-free flaw in the Windows Sockets API driver (afd.sys) that can allow attackers to execute code with SYSTEM-level privileges.
Another serious vulnerability is CVE-2026-62878, a critical Windows DNS Server flaw that allows remote, unauthenticated attackers to execute code with elevated privileges without user interaction. This bug is particularly concerning as it could be wormable and cause widespread incidents if not patched promptly.