Windows 10 1607: 17 Vulnerabilities Disclosed, One Actively Exploited by Lazarus Group
Microsoft patched 17 Windows 10 1607 vulnerabilities on August 11, 2026, including a zero-day exploited by Lazarus Group.

Key findings
- Microsoft Windows 10 1607: 17 vulnerabilities disclosed on August 11, 2026.
- CVE-2026-68820 actively exploited by Lazarus Group in Operation Dream Job campaign.
- Flaws include privilege escalation, denial of service, and information disclosure.
- Multiple "Use After Free" and "Null Pointer Dereference" vulnerabilities addressed.
- Patched in Microsoft's August 2026 security update.
On August 11, 2026, Microsoft released a significant security update addressing 17 vulnerabilities affecting Windows 10 version 1607. This batch of disclosures, all published within a two-minute window, includes a mix of privilege escalation, denial of service, and information disclosure flaws. Notably, one of these vulnerabilities, CVE-2026-68820, was confirmed to be under active exploitation by the North Korean threat actor Lazarus Group as part of their Operation Dream Job campaign, targeting defense and aerospace professionals with fake job offers.
The vulnerabilities can be broadly categorized by their impact. Several "Use After Free" flaws, including CVE-2026-68820, CVE-2026-61346, CVE-2026-59125, and CVE-2026-50472, present opportunities for local privilege escalation. Additionally, "Null Pointer Dereference" vulnerabilities like CVE-2026-59138 and CVE-2026-59132 could lead to denial of service conditions, with CVE-2026-59132 specifically impacting the Windows TCP/IP stack. Information disclosure is also a concern, stemming from vulnerabilities such as CVE-2026-59137 in the Windows Event Logging Service and CVE-2026-59136 in the Windows Search Component.
The exploitation of CVE-2026-68820 by the Lazarus Group, as detailed in multiple security reports, highlights the real-world impact of these disclosures. This vulnerability, a race condition in the Windows Ancillary Function Driver for WinSock (AFD.sys), allowed attackers to gain SYSTEM-level privileges. The campaign, Operation Dream Job, has been ongoing and uses social engineering tactics, such as fake job recruitment on platforms like LinkedIn, to lure victims. The attackers leveraged a post-quantum key exchange to negotiate their command channel before deploying the zero-day exploit.
Microsoft's August 2026 Patch Tuesday addressed these issues, with CVE-2026-68820 being the sole vulnerability confirmed as actively exploited at the time of release. The patches are part of a larger trend of increasing vulnerability disclosures, potentially driven by AI-powered discovery tools, as noted in industry analysis. While specific version information for all affected systems is not detailed for every CVE, the general advice is to apply the August 2026 security updates to mitigate these risks.
Users of Windows 10 version 1607 are urged to apply the latest security updates promptly. The coordinated disclosure of these 17 vulnerabilities underscores the importance of timely patching, especially when a zero-day is actively exploited in sophisticated cyber-espionage campaigns. Continued vigilance and prompt application of security patches are crucial to defend against such threats.
CVE-2026-68820, the actively exploited zero-day, is a critical privilege escalation vulnerability. CVE-2026-59138 and CVE-2026-59132 present denial-of-service risks. Information disclosure vulnerabilities like CVE-2026-59137 and CVE-2026-59136 were also part of this batch. The Lazarus Group's exploitation of CVE-2026-68820 highlights the ongoing threat of state-sponsored cyberattacks. Microsoft's August 2026 Patch Tuesday addressed these 17 vulnerabilities for Windows 10 version 1607. The batch includes multiple "Use After Free" and "Null Pointer Dereference" flaws.