VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 25 CVEs

Windows 11 24H2: 25 Vulnerabilities Patched, Including Exploited Zero-Day CVE-2026-68820

Microsoft patched 25 Windows 11 24H2 vulnerabilities on August 11, 2026, including an actively exploited zero-day (CVE-2026-68820) and multiple privilege escalation flaws.

Key findings

  • Microsoft Windows 11 24H2 patched 25 vulnerabilities on August 11, 2026, including privilege escalation and information disclosure flaws.
  • CVE-2026-68820, a zero-day in Windows Ancillary Function Driver for WinSock, was actively exploited by the Lazarus Group and added to CISA's KEV catalog.
  • Multiple vulnerabilities in Windows Autopilot, Win32K, and NTFS could allow local attackers to elevate privileges or disclose information.
  • Remote code execution is possible via flaws in Windows SSTP (CVE-2026-62889) and GDI+ (CVE-2026-62822).
  • The batch includes a denial-of-service vulnerability in the Windows DHCP Client (CVE-2026-65785).

On August 11, 2026, Microsoft released a significant security update addressing a batch of 25 vulnerabilities affecting Windows 11 24H2. This disclosure event, which occurred within a span of less than two minutes, included a mix of high and medium severity flaws, with a notable emphasis on privilege escalation and information disclosure. The vulnerabilities impact various components of the Windows operating system, including the kernel, networking stack, and core graphical components.

A cluster of vulnerabilities, primarily use-after-free and buffer overflow flaws, target the Windows kernel and related drivers. CVE-2026-65775, CVE-2026-65773, CVE-2026-62894, CVE-2026-62885, CVE-2026-62877, and CVE-2026-62876 are among those that allow local attackers to elevate privileges through various memory corruption techniques within Win32K and other core system components. Additionally, CVE-2026-62832, a flaw in the User Profile Service, also presents a privilege escalation risk.

Several vulnerabilities focus on information disclosure. CVE-2026-65794, a buffer over-read in the Windows SMB Client, and CVE-2026-65784 and CVE-2026-62887, out-of-bounds reads in Windows NTFS, allow unauthorized or authorized attackers to potentially access sensitive data over a network or locally, respectively.

The batch also includes vulnerabilities related to denial of service and remote code execution. CVE-2026-65783, CVE-2026-65781, CVE-2026-65780, CVE-2026-65779, and CVE-2026-65778, all related to Windows Autopilot, present use-after-free and double-free conditions that could lead to privilege escalation. CVE-2026-65783, a resource consumption flaw in the Windows DHCP Client, could lead to a denial of service. More critically, CVE-2026-62889, a double free in the Windows Secure Socket Tunneling Protocol (SSTP), and CVE-2026-62822, an integer overflow in Windows GDI+, could allow remote attackers to execute code.

A particularly concerning vulnerability, CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock, was identified as being actively exploited in the wild. This vulnerability allows a local attacker to elevate privileges. News outlets reported that the North Korean Lazarus Group has been exploiting this zero-day as part of Operation Dream Job, targeting defense and aerospace companies. CISA has added this CVE to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch it.

Microsoft has addressed these vulnerabilities through its August 2026 Patch Tuesday update. Users are strongly advised to apply these patches to mitigate the risks associated with privilege escalation, information disclosure, denial of service, and remote code execution. The comprehensive nature of this batch underscores the importance of timely patching for maintaining system security.

The sheer volume and variety of vulnerabilities disclosed in this single batch highlight the ongoing challenges in securing complex operating systems like Windows. Users should remain vigilant and ensure their systems are updated promptly to protect against both known and emerging threats. The active exploitation of CVE-2026-68820 serves as a stark reminder of the real-world impact of unpatched vulnerabilities.

AI-written article. Grounded in 25 CVE records listed below.