Microsoft Fixes Over 400 Flaws Amid Ongoing Zero-Day Exploit Saga
Microsoft released patches for over 400 security vulnerabilities on August Patch Tuesday, including one actively exploited zero-day and several critical remote code execution flaws that require no user interaction.
The most pressing vulnerability is CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a locally authenticated attacker with low privileges to gain SYSTEM-level access.
This marks the fourth afd.sys zero-day exploited in the wild since 2022, with previous iterations linked to Lazarus Group activity. North Korean attackers have been using this vulnerability in a new wave of the Operation Dream Job campaign to deploy kernel-mode rootkits.