VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 25 CVEs

Microsoft Windows Server 2016: 25 Vulnerabilities Disclosed, Including Actively Exploited Zero-Day

Microsoft's August 11, 2026, Patch Tuesday addressed 25 Windows Server 2016 vulnerabilities, including critical flaws and an actively exploited zero-day used by the Lazarus Group.

Key findings

  • Microsoft Windows Server 2016: 25 vulnerabilities disclosed on August 11, 2026, including critical and high-severity flaws.
  • Multiple vulnerabilities allow for local privilege escalation and remote code execution across various Windows components.
  • CVE-2026-68820, a use-after-free flaw, was actively exploited by the Lazarus Group in targeted attacks.
  • Critical flaws include CVE-2026-62893 in Deployment Services and CVE-2026-65791 in iSCSI Target Service, enabling RCE.
  • The batch consists primarily of memory corruption vulnerabilities like buffer overflows and use-after-free bugs.
  • Users are urged to apply Microsoft's August 2026 security updates to address these issues.

On August 11, 2026, Microsoft released a significant security update addressing 25 vulnerabilities affecting Windows Server 2016. The batch of CVEs, all disclosed on the same day, includes a critical flaw and numerous high-severity issues, primarily related to privilege escalation and remote code execution. This coordinated disclosure highlights ongoing security challenges within the Windows ecosystem.

Several vulnerabilities stem from memory corruption issues within core Windows components. The Windows Installer is implicated in multiple heap-based and stack-based buffer overflows (CVE-2026-70347, CVE-2026-70345, CVE-2026-70344), all allowing local privilege escalation. Similarly, the Windows Ancillary Function Driver for WinSock suffers from use-after-free vulnerabilities (CVE-2026-70307, CVE-2026-68820), also leading to local privilege escalation. The Windows iSCSI Target Service is a notable target, with several vulnerabilities including heap-based buffer overflows that permit network-based code execution (CVE-2026-65796, CVE-2026-65791, CVE-2026-65679) and a null pointer dereference causing a denial of service (CVE-2026-65681).

A critical use-after-free vulnerability in the Windows Deployment Services (CVE-2026-62893) stands out, allowing unauthorized attackers to execute code over a network. Another critical vulnerability, CVE-2026-65791, also a heap-based buffer overflow in the Windows iSCSI Target Service, carries a high CVSS score of 8.1 and allows for network-based code execution.

The batch also includes vulnerabilities affecting other components such as the Desktop Window Manager (CVE-2026-65787, CVE-2026-65786), Windows Win32K (CVE-2026-65775, CVE-2026-65678), and Windows Remote Access API (CVE-2026-65671), predominantly leading to local privilege escalation. Denial-of-service vulnerabilities were also present, including a buffer over-read in the Windows Network File System (CVE-2026-68819) and a null pointer dereference in the Windows iSCSI Target Service (CVE-2026-65681). Information disclosure vulnerabilities were also part of the batch, affecting Windows SMB Client (CVE-2026-65794), Windows NTFS (CVE-2026-65784), and Windows GDI (CVE-2026-65662).

Notably, CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, was actively exploited in the wild prior to its patch. Security advisories from CISA and reports from threat intelligence firms like Check Point Research indicate that the North Korean Lazarus Group has been exploiting this vulnerability as part of their "Operation Dream Job" campaign. This campaign targets professionals in the defense and aerospace sectors with fake job offers to gain initial access and deploy backdoors. The vulnerability allows a local attacker to elevate privileges to SYSTEM.

Microsoft has addressed these vulnerabilities through its August 2026 Patch Tuesday release. Users of Windows Server 2016 and other affected Windows versions are strongly advised to apply the latest security updates immediately to mitigate the risks associated with these flaws. The sheer volume and severity of the vulnerabilities underscore the importance of prompt patching and robust security practices for Windows environments.

This coordinated disclosure of 25 vulnerabilities, including actively exploited ones, emphasizes the persistent threat landscape for Windows Server 2016. Users should prioritize patching to protect against privilege escalation and remote code execution attacks, especially those linked to known threat actors like the Lazarus Group.

Key findings include:

  • A critical use-after-free vulnerability (CVE-2026-62893) in Windows Deployment Services allows network-based code execution.
  • Multiple heap-based buffer overflows in the Windows iSCSI Target Service (e.g., CVE-2026-65791) enable remote code execution.
  • CVE-2026-68820, a use-after-free in Windows Ancillary Function Driver for WinSock, was actively exploited by the Lazarus Group.
  • The majority of disclosed vulnerabilities allow for local privilege escalation on affected systems.
  • The batch includes memory corruption flaws such as buffer overflows and use-after-free bugs across various Windows components.
  • Prompt application of Microsoft's August 2026 security updates is crucial for mitigating these risks.
AI-written article. Grounded in 25 CVE records listed below.