Windows 10 1607: 25 Vulnerabilities Patched, Including Actively Exploited Zero-Day
Microsoft addressed 25 vulnerabilities in Windows 10 1607 on August 11, 2026, including a critical flaw and a zero-day exploited by the Lazarus Group.

Key findings
- Microsoft patched 25 vulnerabilities in Windows 10 1607 on August 11, 2026, including critical and high-severity flaws.
- The batch includes multiple vulnerabilities allowing for local privilege escalation and remote code execution.
- CVE-2026-68820, a use-after-free vulnerability, was actively exploited by the Lazarus Group as a zero-day.
- The Lazarus Group used CVE-2026-68820 in "Operation Dream Job" targeting defense and aerospace sectors.
- CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog.
- The vulnerabilities affect critical Windows components like iSCSI Target Service, Windows Installer, and WinSock driver.
On August 11, 2026, Microsoft released a significant security update addressing 25 vulnerabilities affecting Windows 10 version 1607. The batch of disclosures, all published on the same day, includes a critical flaw and numerous high-severity issues, primarily related to privilege escalation and code execution. The vulnerabilities span various Windows components, including the Windows Installer, Ancillary Function Driver for WinSock, iSCSI Target Service, and others.
A notable vulnerability, CVE-2026-65791, a critical heap-based buffer overflow in the Windows iSCSI Target Service, allows an unauthorized attacker to execute code over a network with a CVSSv3 score of 9.8. This vulnerability, along with others in the iSCSI Target Service (CVE-2026-65796 and CVE-2026-65679), presents a severe risk of remote code execution.
Several vulnerabilities are categorized as heap-based buffer overflows and use-after-free flaws, predominantly leading to local privilege escalation. These include CVE-2026-70347, CVE-2026-70345, CVE-2026-66799, CVE-2026-65790, CVE-2026-65787, CVE-2026-65786, CVE-2026-65775, CVE-2026-65671, and CVE-2026-62894. Additionally, CVE-2026-65773, an improper access control vulnerability in the Windows Kernel, also allows for local privilege escalation.
The batch also includes vulnerabilities that could lead to information disclosure or denial of service. CVE-2026-65794 and CVE-2026-65662 are buffer over-read flaws in the Windows SMB Client and Windows GDI, respectively, allowing for information disclosure. CVE-2026-68819, a buffer over-read in the Windows Network File System, and CVE-2026-65681, a null pointer dereference in the Windows iSCSI Target Service, can result in denial of service.
One vulnerability from this batch, CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock, was actively exploited in the wild prior to its patching. News reports indicate that the North Korean Lazarus Group utilized this vulnerability as a zero-day in their "Operation Dream Job" campaign, targeting professionals in the defense and aerospace sectors. CISA added this vulnerability to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch it within two weeks.
Microsoft's August 2026 Patch Tuesday addressed these vulnerabilities, with fixes integrated into the cumulative updates. Users of Windows 10 version 1607 are strongly advised to apply these updates immediately to mitigate the risks associated with these privilege escalation and code execution vulnerabilities. The sheer volume and severity of the disclosed flaws underscore the importance of timely patching and proactive security measures.
Key findings from this disclosure event include:
- A critical CVE-2026-65791 and multiple high-severity RCE vulnerabilities in the iSCSI Target Service.
- A significant number of privilege escalation flaws across various Windows components.
- Active exploitation of CVE-2026-68820 by the Lazarus Group, highlighting the real-world threat posed by zero-day vulnerabilities.
- The batch includes vulnerabilities leading to privilege escalation, code execution, information disclosure, and denial of service.
- All 25 vulnerabilities were patched by Microsoft on August 11, 2026.
The vulnerabilities disclosed in this batch are: CVE-2026-70347, CVE-2026-70345, CVE-2026-70344, CVE-2026-70307, CVE-2026-68820, CVE-2026-68819, CVE-2026-66804, CVE-2026-66799, CVE-2026-65814, CVE-2026-65796, CVE-2026-65794, CVE-2026-65791, CVE-2026-65790, CVE-2026-65787, CVE-2026-65786, CVE-2026-65784, CVE-2026-65775, CVE-2026-65773, CVE-2026-65681, CVE-2026-65679, CVE-2026-65678, CVE-2026-65671, CVE-2026-65662, CVE-2026-62908, CVE-2026-62894.
A stylized Windows 10 logo is depicted with several critical components highlighted in red, indicating vulnerabilities, with a lock icon breaking apart to symbolize privilege escalation.