Microsoft Patches Over 400 Vulnerabilities in August 2026 Patch Tuesday
Microsoft released its August 2026 Patch Tuesday fixes for over 400 vulnerabilities in Windows and other products. Among them is CVE-2026-68820, a zero-day exploit that has been used by North Korean attackers to deploy a kernel-mode rootkit as part of the Operation Dream Job campaign.
The vulnerability affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a low-privileged local attacker to elevate privileges to SYSTEM. Microsoft explained that an authenticated attacker could run a specially crafted application on an affected system, triggering a race condition without requiring user interaction.
Other vulnerabilities of note include CVE-2026-62832, which affects the Windows User Profile Service and may allow an authenticated attacker to achieve Admin privileges; and CVE-2026-72971, which affects Windows Container Isolation FS Filter Driver (unionfs.sys) on ARM64-based Systems.