VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 17 CVEs

Microsoft Windows 11: 17 Vulnerabilities Patched, One Actively Exploited by Lazarus Group

Microsoft patched 17 Windows 11 23H2 vulnerabilities on August 11, 2026, including CVE-2026-68820, actively exploited by the Lazarus Group.

Key findings

  • Microsoft Windows 11 23H2: 17 vulnerabilities disclosed on August 11, 2026, including privilege escalation and DoS flaws.
  • CVE-2026-68820 actively exploited by Lazarus Group in 'Operation Dream Job' targeting defense sector.
  • Vulnerabilities affect core Windows components like WinSock, Graphics Kernel, and Event Logging Service.
  • Patches available in Microsoft's August 2026 Patch Tuesday release.
  • CISA mandates urgent patching of CVE-2026-68820 for federal agencies.

On August 11, 2026, Microsoft released a significant security update addressing 17 vulnerabilities affecting Windows 11 23H2. This batch of disclosures includes a mix of privilege escalation, denial-of-service, and information disclosure flaws, with several rated as High severity. Notably, one of these vulnerabilities, CVE-2026-68820, was confirmed to be under active exploitation in the wild by the Lazarus Group as part of the "Operation Dream Job" campaign, targeting defense and aerospace companies.

The disclosed vulnerabilities span various Windows components. Privilege escalation was a common theme, with flaws like CVE-2026-68820 (Use after free in Windows Ancillary Function Driver for WinSock), CVE-2026-61346 (Use after free in Windows Graphics Kernel), CVE-2026-59126 (Race condition in Windows Event Logging Service), CVE-2026-59125 (Use after free in Virtual Hard Disk Miniport Driver), CVE-2026-59122 (Race condition in Windows Telephony Service), CVE-2026-56174 (Untrusted search path in Windows Narrator Braille), and CVE-2026-50472 (Heap-based buffer overflow in Windows LUAFV) allowing local attackers to gain elevated privileges.

Denial-of-service (DoS) vulnerabilities were also present, including CVE-2026-59132 (Null pointer dereference in Windows TCP/IP) and CVE-2026-54113 (Allocation of resources without limits or throttling in Windows Kernel). Additionally, several information disclosure vulnerabilities were patched, such as CVE-2026-59137 and CVE-2026-59136 (Use of uninitialized resource in Windows Event Logging Service and Microsoft COM for Windows, respectively), CVE-2026-59135 (Weak authentication in Windows Search Component), CVE-2026-59128 (Out-of-bounds read in Windows Encrypting File System), and CVE-2026-59131 and CVE-2026-59130 (issues in AMD Zen). CVE-2026-54984, a heap-based buffer overflow in Windows Imaging Component, could allow an attacker to execute code locally.

The exploitation of CVE-2026-68820 by the Lazarus Group, a state-sponsored threat actor linked to North Korea, highlights the immediate risk posed by this batch. This campaign, known as Operation Dream Job, involves luring victims with fake job offers on platforms like LinkedIn, ultimately aiming to steal sensitive data and deploy malware, including a new backdoor and a kernel-mode rootkit. The vulnerability itself, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allows a local attacker to elevate privileges to SYSTEM. Microsoft has addressed all these vulnerabilities in its August 2026 Patch Tuesday release. Users are strongly advised to apply these updates to protect against potential exploitation.

The batch of 17 CVEs were all disclosed on August 11, 2026, with the actively exploited CVE-2026-68820 being a particular focus for security advisories and government directives, such as CISA's order for federal agencies to patch the vulnerability within two weeks. This coordinated disclosure and rapid exploitation underscore the evolving threat landscape and the importance of timely patching.

Key findings from this disclosure include:

  • A batch of 17 vulnerabilities affecting Windows 11 23H2 were disclosed on August 11, 2026.
  • CVE-2026-68820, a privilege escalation vulnerability, was actively exploited by the Lazarus Group in the "Operation Dream Job" campaign.
  • The vulnerabilities include several privilege escalation flaws, DoS issues, and information disclosure bugs across various Windows components.
  • Microsoft has released patches for all disclosed vulnerabilities as part of its August 2026 Patch Tuesday update.
  • CISA has mandated federal agencies to patch CVE-2026-68820 due to active exploitation.

The vulnerabilities patched in this batch include CVE-2026-68820, CVE-2026-61346, CVE-2026-59138, CVE-2026-59137, CVE-2026-59136, CVE-2026-59135, CVE-2026-59132, CVE-2026-59131, CVE-2026-59130, CVE-2026-59128, CVE-2026-59126, CVE-2026-59125, CVE-2026-59122, CVE-2026-56174, CVE-2026-54984, CVE-2026-54113, and CVE-2026-50472.

AI-written article. Grounded in 17 CVE records listed below.
Microsoft Windows 11: 17 Vulnerabilities Patched, One Actively Exploited by Lazarus Group · VYPR