Microsoft Fixes Over 420 Flaws in August Patch Tuesday
Microsoft has released its largest security update of the year so far, patching over 420 vulnerabilities in Windows 11. The August Patch Tuesday release includes a critical kernel driver flaw that was being exploited by North Korea's Lazarus Group before Microsoft shipped the patches.
The most urgent fix is CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). This flaw allows an attacker to gain SYSTEM privileges without user interaction. Check Point Research reported that Lazarus Group exploited this vulnerability as part of its Operation Dream Job campaign.
Another critical patch is CVE-2026-62832, which lets an authenticated attacker force the Windows User Profile Service to load another local account's registry hive, granting unauthorized access to administrator rights.