Windows 11 26h1: 17 Vulnerabilities Patched, One Exploited by Lazarus Group
Microsoft's August 2026 Patch Tuesday addresses 17 Windows 11 26h1 vulnerabilities, including one actively exploited by the Lazarus Group.

Key findings
- Microsoft patched 17 Windows 11 26h1 vulnerabilities on August 11, 2026.
- CVE-2026-68820, a privilege escalation flaw, is actively exploited by Lazarus Group in Operation Dream Job.
- The batch includes privilege escalation, DoS, and information disclosure vulnerabilities.
- Key affected components include WinSock, TCP/IP, and the Windows Kernel.
- Users are urged to apply the August 2026 security updates promptly.
On August 11, 2026, Microsoft released a significant security update addressing 17 vulnerabilities in Windows 11 26h1. The batch includes a mix of privilege escalation, denial of service, and information disclosure flaws, with several rated as High severity. Notably, one of these vulnerabilities, CVE-2026-68820, was confirmed to be under active exploitation in the wild by the Lazarus Group as part of their Operation Dream Job campaign. This campaign targets professionals in the defense and aerospace sectors using sophisticated social engineering tactics, including fake job offers.
The vulnerabilities disclosed can be broadly categorized by their impact. Several "Use After Free" vulnerabilities, including CVE-2026-68820, CVE-2026-61346, CVE-2026-59125, and CVE-2026-50472, allow local attackers to elevate privileges. CVE-2026-68820 specifically affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and was exploited by Lazarus to deploy a rootkit. Another privilege escalation vulnerability, CVE-2026-59122, stems from a race condition in the Windows Telephony Service.
Denial of Service (DoS) vulnerabilities were also present in this batch. CVE-2026-59132, a null pointer dereference in Windows TCP/IP, allows an unauthorized attacker to cause a DoS over a network. Similarly, CVE-2026-54113, an allocation of resources without limits in the Windows Kernel, can lead to a DoS.
Information disclosure vulnerabilities are also a concern. CVE-2026-59137 and CVE-2026-59136, related to the use of uninitialized resources in the Windows Event Logging Service and Microsoft COM for Windows respectively, allow local attackers to disclose information. CVE-2026-59135, a weak authentication flaw in the Windows Search Component, also leads to local information disclosure. CVE-2026-59131 and CVE-2026-59130, affecting AMD Zen, and CVE-2026-59128, an out-of-bounds read in the Windows Encrypting File System (EFS), also fall into this category.
Microsoft addressed a critical heap-based buffer overflow in the Windows Imaging Component (CVE-2026-54984), which could allow a local attacker to execute code. Additionally, CVE-2026-56179, an origin validation error in Windows Network Address Translation (NAT), permits spoofing over an adjacent network.
Microsoft's August Patch Tuesday addressed these vulnerabilities, with CVE-2026-68820 being the sole vulnerability confirmed to be under active exploitation. The company has provided patches for all disclosed vulnerabilities, and users are strongly advised to update their systems to the latest versions to mitigate these risks. The active exploitation of CVE-2026-68820 by a sophisticated threat actor like Lazarus highlights the importance of timely patching, especially for vulnerabilities that are being weaponized in ongoing campaigns.
The disclosure of this batch of vulnerabilities, particularly the actively exploited CVE-2026-68820, underscores the persistent threat landscape for Windows users. The Lazarus Group's use of this vulnerability in Operation Dream Job demonstrates a targeted approach to espionage, leveraging social engineering to gain initial access. The wide range of vulnerabilities, from privilege escalation to DoS and information disclosure, indicates a broad attack surface within the Windows operating system. Users should remain vigilant and ensure their systems are updated promptly to protect against these threats. The sheer volume of vulnerabilities patched by Microsoft each month, as noted in related coverage, also points to the increasing complexity of software development and the ongoing challenge of maintaining robust security.