Microsoft Server 2019: 16 Flaws Patched, Zero-Day Exploited by Lazarus Group
Microsoft addressed 16 Windows Server 2019 vulnerabilities on August 11, 2026, including a zero-day exploited by Lazarus Group.

Key findings
- Microsoft patched 16 vulnerabilities in Windows Server 2019 on August 11, 2026.
- CVE-2026-68820, a use-after-free flaw in WinSock, is actively exploited by Lazarus Group.
- Multiple vulnerabilities allow for local privilege escalation and information disclosure.
- The Lazarus Group's Operation Dream Job targets defense and aerospace sectors.
- CISA has mandated patching for federal agencies due to CVE-2026-68820 exploitation.
On August 11, 2026, Microsoft released a significant security update addressing 16 vulnerabilities in Windows Server 2019, disclosed on the same day. The batch includes a mix of high and medium severity flaws, with a notable focus on privilege escalation and information disclosure. The most critical of these, CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, was confirmed to be under active exploitation by the Lazarus Group as part of Operation Dream Job, a cyber-espionage campaign targeting defense and aerospace professionals. This particular vulnerability allows a local attacker to elevate privileges to SYSTEM level.
Several vulnerabilities in this batch revolve around memory corruption issues. CVE-2026-68820, CVE-2026-61346, CVE-2026-59132, CVE-2026-59122, CVE-2026-56174, CVE-2026-54984, and CVE-2026-50472 are all related to use-after-free, null pointer dereference, race conditions, or buffer overflows, with many enabling local privilege escalation. Additionally, CVE-2026-59125, a use-after-free in the Virtual Hard Disk (VHD) Miniport Driver, also allows for local privilege escalation.
Information disclosure vulnerabilities are also prevalent, with CVE-2026-59137, CVE-2026-59136, CVE-2026-59131, CVE-2026-59130, and CVE-2026-59128 allowing unauthorized access to sensitive data through various components like the Event Logging Service, COM for Windows, Windows Search Component, and the Encrypting File System (EFS). A denial-of-service (DoS) vulnerability, CVE-2026-59135, affects the Microsoft Remote Registry Service, while CVE-2026-54113, an allocation of resources without limits, also presents a DoS risk.
The active exploitation of CVE-2026-68820 by the Lazarus Group highlights the immediate threat posed by this batch. This campaign, Operation Dream Job, involves fake job offers to lure employees in the defense and aerospace sectors, as reported by multiple sources including The Hacker News and Infosecurity Magazine. CISA has issued directives for federal agencies to patch this vulnerability promptly. Microsoft's August Patch Tuesday addressed these issues, with patches available for all affected systems. Users are strongly advised to apply these updates to mitigate the risk of exploitation and protect against privilege escalation and information disclosure.
This coordinated disclosure of multiple vulnerabilities underscores the importance of timely patching. The presence of an actively exploited zero-day, CVE-2026-68820, emphasizes the need for vigilance, especially for organizations in sensitive sectors like defense and aerospace. Users should ensure their Windows Server 2019 environments are updated to the latest security patches to prevent potential compromise.