Microsoft Patch Tuesday Fixes Over 400 Vulnerabilities
Microsoft's August Patch Tuesday released security fixes for over 400 vulnerabilities, including one that has been exploited in zero-day attacks. The vulnerability, CVE-2026-68820, is a use-after-free flaw affecting the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a low-privileged local attacker to elevate privileges to SYSTEM.
The vulnerability was reportedly exploited by North Korean attackers as part of the Operation Dream Job campaign. Microsoft explained that an authenticated attacker could run a specially crafted application on an affected system, triggering a race condition and no user interaction is required.
Additionally, three vulnerabilities were publicly disclosed prior to the release of patches: CVE-2026-62832, which affects the Windows User Profile Service; CVE-2026-72971, affecting the Windows Container Isolation FS Filter Driver (unionfs.sys) for ARM64-based Systems; and CVE-2026-62737, an elevation of privilege vulnerability affecting the Windows kernel.
Microsoft also fixed several other vulnerabilities, including a critical Microsoft QUIC vulnerability (CVE-2026-62815), a stack-based buffer overflow in Windows DNS (CVE-2026-62878), and a Sharepoint flaw (CVE-2026-63520) that can be used to achieve unauthenticated remote code execution.
Security experts are cautioning against rushing into patching, advising IT admins and security teams to carefully evaluate the patches and prioritize those with high CVSS scores. Ivanti's Chris Goettl noted that while there is an explosion of bugs being reported, there has been no equivalent increase in actively exploited vulnerabilities.