Windows Server 2025: 25 Vulnerabilities Patched, Including Exploited Zero-Day
Microsoft disclosed 25 vulnerabilities in Windows Server 2025 on August 11, 2026, including a critical RCE flaw and an actively exploited zero-day.

Key findings
- Microsoft patched 25 vulnerabilities in Windows Server 2025 on August 11, 2026, including critical flaws.
- Multiple vulnerabilities allow local privilege escalation, with several involving heap-based buffer overflows and use-after-free bugs.
- CVE-2026-68820, a use-after-free flaw, was actively exploited by the Lazarus Group in targeted attacks.
- The batch includes a critical RCE vulnerability in the Windows iSCSI Target Service (CVE-2026-65791).
- CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog.
On August 11, 2026, Microsoft released a significant batch of 25 security advisories addressing vulnerabilities in Windows Server 2025 and other Windows components. This coordinated disclosure event, spanning less than a minute, highlights a concentrated effort to patch critical flaws, with many of the vulnerabilities allowing for local privilege escalation. The batch includes a critical-rated heap-based buffer overflow in the Windows iSCSI Target Service, CVE-2026-65791, which could allow an unauthorized attacker to execute code over a network.
Several vulnerabilities cluster around buffer overflow and use-after-free conditions, primarily affecting core Windows components. The Windows Installer is implicated in multiple heap-based buffer overflows (CVE-2026-70347, CVE-2026-70345) and a stack-based buffer overflow (CVE-2026-70344), all rated High and allowing local privilege escalation. Similarly, the Windows Ancillary Function Driver for WinSock (AFD.sys) is affected by use-after-free vulnerabilities (CVE-2026-70307, CVE-2026-68820), also leading to local privilege escalation. The Windows iSCSI Target Service, besides the critical RCE vulnerability, also suffers from a heap-based buffer overflow (CVE-2026-65679) and a null pointer dereference leading to denial of service (CVE-2026-65681).
Notably, CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, was actively exploited in the wild prior to its patching. Security advisories from CISA, The Hacker News, and Infosecurity Magazine indicate that the North Korean Lazarus Group exploited this vulnerability as part of their "Operation Dream Job" campaign. This campaign targeted professionals in the defense and aerospace sectors with fake job offers, using the zero-day exploit to gain SYSTEM access and deploy backdoors. CISA has since added CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch it within two weeks.
Other vulnerabilities in this batch include denial-of-service flaws in the Windows Network File System (CVE-2026-68819) and Windows DHCP Client (CVE-2026-65785), information disclosure vulnerabilities in the Windows SMB Client (CVE-2026-65794) and Windows NTFS (CVE-2026-65784), and a security feature bypass in Windows Active Directory (CVE-2026-65777). Privilege escalation vulnerabilities were also found in the Windows Key Guard (CVE-2026-66799), Windows Storage Port Driver (CVE-2026-65814), Windows Message Queuing (CVE-2026-65790), Desktop Window Manager (CVE-2026-65788, CVE-2026-65787, CVE-2026-65786), Windows Win32K (CVE-2026-65776, CVE-2026-65775, CVE-2026-65678), Windows Kernel (CVE-2026-65773), and Windows Remote Access API (CVE-2026-65672).
Microsoft addressed these vulnerabilities through its August 2026 Patch Tuesday release. While specific patch versions are not detailed for each CVE, the coordinated nature of the disclosure suggests that applying the latest cumulative updates for Windows Server 2025 and other affected Windows versions is the recommended mitigation. Users are advised to prioritize patching, especially given the active exploitation of CVE-2026-68820. The sheer volume and severity of these vulnerabilities underscore the importance of timely patching and robust security practices for Windows environments.
The batch of 25 vulnerabilities disclosed on August 11, 2026, represents a critical update for Windows Server 2025 and other Windows systems. The prevalence of privilege escalation flaws, coupled with a network-exploitable code execution vulnerability and an actively exploited zero-day, necessitates immediate attention from administrators. The involvement of sophisticated threat actors like Lazarus Group in exploiting CVE-2026-68820 highlights the real-world impact of these disclosures. Users should ensure their systems are updated to mitigate these risks and stay vigilant against ongoing threats.