Microsoft Windows 11 25H2: 17 Flaws Patched, Including Exploited Zero-Day CVE-2026-68820
Microsoft's August 2026 Patch Tuesday addresses 17 Windows 11 25H2 vulnerabilities, including a critical zero-day (CVE-2026-68820) exploited by Lazarus Group.

Key findings
- Microsoft Windows 11 25H2: 17 vulnerabilities disclosed on August 11, 2026.
- CVE-2026-68820: Actively exploited zero-day by Lazarus Group used in Operation Dream Job targeting defense sector.
- Vulnerabilities include privilege escalation, code execution, DoS, and information disclosure.
- High severity flaws like CVE-2026-54984 (RCE) and CVE-2026-56179 (Spoofing) also present.
- Urgent patching advised, especially for CVE-2026-68820, with CISA directives issued.
Microsoft released its August 2026 Patch Tuesday, addressing a significant batch of 17 vulnerabilities affecting Windows 11 25H2. The disclosures occurred on August 11, 2026, with a tight disclosure window of zero hours. Among these, CVE-2026-68820 stands out as a critical zero-day vulnerability actively exploited in the wild by the Lazarus Group as part of Operation Dream Job, a campaign targeting defense and aerospace professionals with fake job offers. This exploitation highlights the immediate threat posed by unpatched systems.
The vulnerabilities span various categories, including privilege escalation, denial of service, and information disclosure. Several "use after free" vulnerabilities, such as CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock and CVE-2026-61346 in the Windows Graphics Kernel, allow local attackers to elevate privileges. Another critical vulnerability, CVE-2026-54984, a heap-based buffer overflow in the Windows Imaging Component, could allow unauthorized attackers to execute code locally.
Denial of service vulnerabilities include CVE-2026-59132, a null pointer dereference in Windows TCP/IP, and CVE-2026-54113, an allocation of resources without limits in the Windows Kernel. Information disclosure vulnerabilities are also present, such as CVE-2026-59137 and CVE-2026-59136 related to uninitialized resources in Windows Event Logging Service and Microsoft COM for Windows, respectively. Weak authentication in the Windows Search Component (CVE-2026-59135) also contributes to information disclosure risks.
The active exploitation of CVE-2026-68820 by the Lazarus Group, a North Korean threat actor, is a major concern. This vulnerability was used to deliver a new backdoor and target defense and aerospace companies across multiple countries. Security agencies like CISA have issued urgent directives for federal agencies to patch this specific vulnerability. The exploitation involves a race condition in AFD.sys, the network socket driver, allowing a low-privileged local attacker to gain SYSTEM privileges.
Microsoft's August 2026 Patch Tuesday addresses these issues across various Windows components. While specific version numbers for affected and patched software are not detailed in the provided information, users are strongly advised to apply all available security updates promptly. The sheer volume of vulnerabilities disclosed, with 62 critical and 357 important-rated issues in this release alone, underscores the ongoing challenges in maintaining system security.
This batch of vulnerabilities, particularly the actively exploited CVE-2026-68820, emphasizes the critical need for timely patching and robust security practices. The involvement of sophisticated threat actors like Lazarus Group in exploiting zero-day flaws highlights the persistent risks faced by organizations, especially those in sensitive sectors like defense and aerospace. Users should prioritize updating their Windows 11 25H2 systems to mitigate these risks.
The batch includes:
- Privilege Escalation: CVE-2026-68820, CVE-2026-61346, CVE-2026-59126, CVE-2026-59125, CVE-2026-59122, CVE-2026-50472
- Code Execution: CVE-2026-54984
- Denial of Service: CVE-2026-59138, CVE-2026-59132, CVE-2026-54113
- Information Disclosure: CVE-2026-59137, CVE-2026-59136, CVE-2026-59135, CVE-2026-59131, CVE-2026-59130, CVE-2026-59128
- Spoofing: CVE-2026-56179
The Lazarus Group's exploitation of CVE-2026-68820 in Operation Dream Job is a significant event, demonstrating the real-world impact of these vulnerabilities. The campaign uses social engineering tactics, such as fake job offers, to lure victims and deploy malware. The vulnerability itself is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), allowing privilege escalation. Microsoft's prompt patching, alongside advisories from CISA, aims to curb further exploitation.
The broader context of this disclosure includes a massive Patch Tuesday release from Microsoft, with over 400 vulnerabilities addressed. This trend, partly attributed to AI-powered vulnerability discovery, presents a continuous challenge for IT security teams. The focus remains on users applying the August 2026 security updates to protect against these threats.