VYPR
Vypr IntelligenceAI-generatedAug 11, 2026· 25 CVEs

Windows 11 26h1: 25 Vulnerabilities Patched, Including Actively Exploited Privilege Escalation Flaw

Microsoft addressed 25 Windows 11 26h1 vulnerabilities on August 11, 2026, including actively exploited flaws allowing privilege escalation.

Key findings

  • Microsoft patched 25 vulnerabilities in Windows 11 26h1 on August 11, 2026.
  • Multiple high-severity vulnerabilities allow local privilege escalation via buffer overflows and use-after-free flaws.
  • CVE-2026-68820, a use-after-free vulnerability, was actively exploited by the Lazarus Group in targeted attacks.
  • CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog.
  • Users are urged to apply the August 2026 security updates to protect against these threats.

On August 11, 2026, Microsoft released a significant security update addressing 25 vulnerabilities in Windows 11 26h1. The batch, disclosed on the same day, includes a mix of high and medium severity flaws, with a particular focus on elevation of privilege and buffer overflow vulnerabilities. The timely release of these patches is crucial for users to protect their systems from potential local attacks.

Several vulnerabilities stem from issues within the Windows Installer component, including heap-based buffer overflows (CVE-2026-70347, CVE-2026-70345) and a stack-based buffer overflow (CVE-2026-70344), all rated as High severity and allowing for local privilege escalation. Additionally, use-after-free vulnerabilities were identified in various Windows components, such as the Ancillary Function Driver for WinSock (CVE-2026-70307, CVE-2026-68820), Desktop Window Manager (CVE-2026-65788, CVE-2026-65787, CVE-2026-65786), Autopilot (CVE-2026-65780, CVE-2026-65779), and Win32K (CVE-2026-65776, CVE-2026-65775, CVE-2026-65678). These also carry High severity ratings and permit local privilege escalation.

A notable vulnerability, CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock, was actively exploited in the wild by the North Korean Lazarus Group as part of the "Operation Dream Job" campaign. This campaign targeted professionals in the defense and aerospace sectors with fake job offers. CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog, urging federal agencies to patch it within two weeks. The exploitation allowed attackers to gain SYSTEM access and deploy backdoors or rootkits.

Other vulnerabilities in this batch include improper link resolution in the Windows Container Isolation FS Filter Driver (CVE-2026-72971) and Windows Management Services (CVE-2026-70348), both rated Medium. Information disclosure vulnerabilities were also present, such as a buffer over-read in the Windows SMB Client (CVE-2026-65794) and an out-of-bounds read in Windows NTFS (CVE-2026-65784). A medium-severity vulnerability in Windows Active Directory (CVE-2026-65777) involved inadequate encryption strength, potentially allowing bypass of security features.

Microsoft has addressed all these vulnerabilities in its August 2026 Patch Tuesday release. Users are strongly advised to update their Windows 11 26h1 systems to the latest available version to mitigate the risks associated with these flaws. The widespread nature of these vulnerabilities, particularly those allowing privilege escalation, underscores the importance of prompt patching to maintain system security.

Key Findings:

  • Microsoft patched 25 vulnerabilities in Windows 11 26h1 on August 11, 2026.
  • Multiple high-severity vulnerabilities allow local privilege escalation via buffer overflows and use-after-free flaws.
  • CVE-2026-68820, a use-after-free vulnerability, was actively exploited by the Lazarus Group in targeted attacks.
  • CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog.
  • The batch includes vulnerabilities affecting core Windows components like Installer, WinSock, and Win32K.
  • Users are urged to apply the August 2026 security updates to protect against these threats.
AI-written article. Grounded in 25 CVE records listed below.