High severity7.0CISA KEVNVD Advisory· Published Aug 11, 2026· Updated Aug 16, 2026
CVE-2026-68820
CVE-2026-68820
Description
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*+ 3 more
- cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*range: <10.0.14393.9418
- cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*range: <10.0.14393.9418
- cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*range: <10.0.19044.7663
- cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*range: <10.0.19045.7663
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*+ 1 more
- cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*range: <10.0.17763.9115
- cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*range: <10.0.17763.9115
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*Range: <10.0.14393.9418
- cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*Range: <10.0.17763.9115
- cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*Range: <10.0.20348.5440
- cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*Range: <10.0.26100.33222
Patches
Vulnerability mechanics
References
2- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820nvdPatchVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
50- Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code ExecutionThe Hacker News · Aug 21, 2026
- 17th August – Threat Intelligence ReportCheck Point Research · Aug 17, 2026
- ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and MoreThe Hacker News · Aug 17, 2026
- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 StoriesCyber Security News · Aug 16, 2026
- Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayHelp Net Security · Aug 16, 2026
- CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in AttacksCyber Security News · Aug 13, 2026
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy BackdoorThe Hacker News · Aug 12, 2026
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-DayInfosecurity Magazine · Aug 12, 2026
- Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discoveryThe Record · Aug 12, 2026
- CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaignThe Record · Aug 12, 2026
- Lazarus hackers pair fake job offers with Windows zero-day exploitHelp Net Security · Aug 12, 2026
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Help Net Security · Aug 12, 2026
- Fresh Windows Zero-Day Exploited in North Korean CyberattacksSecurityWeek · Aug 12, 2026
- Microsoft Fixes 400 Flaws on August Patch TuesdayInfosecurity Magazine · Aug 12, 2026
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM AccessThe Hacker News · Aug 12, 2026
- Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule RootkitCyber Security News · Aug 12, 2026
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Intelligence · Aug 11, 2026
- Microsoft's Patch Tuesday Deluge Continues With August UpdatesDark Reading · Aug 11, 2026
- 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked oneThe Register Security · Aug 11, 2026
- Microsoft Plugs Nearly 400 Security HolesKrebs on Security · Aug 11, 2026
- Patch Tuesday - August 2026Rapid7 Blog · Aug 11, 2026
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active AttackThe Hacker News · Aug 11, 2026
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DaySecurityWeek · Aug 11, 2026
- Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)Tenable Blog · Aug 11, 2026
- Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)SANS Internet Storm Center · Aug 11, 2026
- Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-DaysCyber Security News · Aug 11, 2026
- Shattering the Dream – When a Job Offer Becomes a Zero-Day AttackCheck Point Research · Aug 11, 2026
- Windows 11 26h1: 25 Vulnerabilities Patched, Including Actively Exploited Privilege Escalation FlawVypr Intelligence · Aug 11, 2026
- Microsoft Windows 11 24H2: 25 Vulnerabilities Patched, Including Actively Exploited Zero-DayVypr Intelligence · Aug 11, 2026
- Windows Server 2025: 25 Vulnerabilities Patched, Including Exploited Zero-DayVypr Intelligence · Aug 11, 2026
- Microsoft Windows Server 2016: 25 Vulnerabilities Disclosed, Including Actively Exploited Zero-DayVypr Intelligence · Aug 11, 2026
- Microsoft Windows Server 2012: 25 Vulnerabilities Disclosed, Zero-Day ExploitedVypr Intelligence · Aug 11, 2026
- Windows 10 1607: 25 Vulnerabilities Patched, Including Actively Exploited Zero-DayVypr Intelligence · Aug 11, 2026
- Microsoft Windows DNS: 16 Vulnerabilities Disclosed Together, Ranging to Critical Remote Code ExecutionVypr Intelligence · Aug 11, 2026
- Microsoft Office Excel: 25 Vulnerabilities Disclosed Together in August Patch TuesdayVypr Intelligence · Aug 11, 2026
- Microsoft Office: 25 Vulnerabilities Disclosed Together, Including High-Severity FlawsVypr Intelligence · Aug 11, 2026
- Microsoft Office 2016: 14 Vulnerabilities Including RCE Flaws Disclosed TogetherVypr Intelligence · Aug 11, 2026
- Microsoft Server 2016: 14 Flaws Patched, One Actively Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Microsoft Windows 11: 17 Vulnerabilities Patched, One Actively Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Windows 10 1607: 17 Vulnerabilities Disclosed, One Actively Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Windows 11 24H2: 25 Vulnerabilities Patched, Including Exploited Zero-Day CVE-2026-68820Vypr Intelligence · Aug 11, 2026
- Microsoft Windows 11 25H2: 17 Flaws Patched, Including Exploited Zero-Day CVE-2026-68820Vypr Intelligence · Aug 11, 2026
- Windows 11 24H2: 17 Vulnerabilities Patched, One Actively Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Windows Server 2003: 17 Vulnerabilities Disclosed, One Actively Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Windows 11 26h1: 17 Vulnerabilities Patched, One Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Windows Server 2012: 13 Vulnerabilities Patched, One Actively Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Microsoft Server 2019: 16 Flaws Patched, Zero-Day Exploited by Lazarus GroupVypr Intelligence · Aug 11, 2026
- Microsoft Windows: 8 Flaws Including Privilege Escalation Disclosed Together in August 2026 Patch TuesdayVypr Intelligence · Aug 11, 2026
- Microsoft CVE-2026-68820 Added to CISA KEV Under Active ExploitationVypr Intelligence · Aug 11, 2026
- August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEsCrowdStrike Blog