Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft security patch release for CVE-2026-68820

Security Patch Release
First reported
Last updated
Happening score
H score 28
3 unique sources, 4 articles

Summary

Hide ▲

Microsoft released August 2026 Patch Tuesday updates for Windows operating systems and supported software, fixing at least 398 vulnerabilities. The bundle includes CVE-2026-68820, an actively exploited privilege-escalation zero-day in Windows Ancillary Function Driver for WinSock (AFD.sys) that can raise a locally authenticated user to SYSTEM. Microsoft also flagged CVE-2026-62832 as likely to be exploited and CVE-2026-72971 as a publicly disclosed lower-impact flaw.

Related Happenings

Microsoft security patch release for CVE-2026-62832

Security Patch Release
H score5 First: 12.08.2026 09:41 Last: 12.08.2026 09:41 Sources 1

How related: CVE-2026-62832 is an Elevation of Privilege (EoP) vulnerability in the Windows User Profile Service which could allow an authenticated local attacker to elevate privileges.

About this happening: Microsoft shipped patches for 421 security flaws, including 236 flaws in Windows, as part of a broad update that also remediates multiple named CVEs. The release cover...

Microsoft August 2026 Patch Tuesday security updates (3 zero-days)

Security Patch Release
H score39 First: 11.08.2026 21:08 Last: 11.08.2026 21:08 Sources 1

About this happening: Microsoft's August 2026 Patch Tuesday fixes 398 CVEs, including CVE-2026-68820, a Windows kernel driver use-after-free in AFD.sys that is under active ex...

Latest development: 12.08.2026 16:35

Lazarus group malware used a post-quantum key exchange to negotiate its command channel, then pulled down a Windows zero-day exploit in an Operation Dream Job campaign against defense and aerospace companies in Europe and India. The chain ran through MISTPEN, an in-memory downloader that fetched FudModule v3.1, a kernel rootkit that disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, blinds 94 ETW providers, and tampers with Smart App Control; the same infrastructure also used RelayShell and impersonation sites for Enveil to distribute Troy.

Microsoft AD CS security update for CVE-2026-54121

Security Patch Release
H score34 First: 24.07.2026 17:15 Last: 24.07.2026 17:15 Sources 1

About this happening: Certighost (CVE-2026-54121) is a Microsoft Active Directory Certificate Services (AD CS) vulnerability that lets a low-privileged Active Directory user abuse chase f...

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score79 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

Microsoft releases RoguePlanet Defender security update for CVE-2026-50656

Security Patch Release
H score32 First: 17.06.2026 20:36 Last: 17.06.2026 20:36 Sources 1

About this happening: Microsoft Defender security updates for CVE-2026-50656 remediated RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.d...

Latest development: 09.07.2026 11:48

Microsoft released security updates for CVE-2026-50656, remediating the RoguePlanet privilege-escalation flaw in Microsoft Malware Protection Engine (mpengine.dll) with version 1.1.26060.3008 and additional defense-in-depth updates. Microsoft said no customer action is required to install the update.

Timeline

  1. 12.08.2026 00:28 5 articles · 13d ago

    Microsoft releases Windows security updates for 398 vulnerabilities

    Initial Disclosure

    Microsoft released updates for Windows operating systems and supported software, fixing at least 398 security vulnerabilities. The patch set includes CVE-2026-68820, an actively exploited privilege-escalation zero-day in afd.sys, along with CVE-2026-62832, which Microsoft says is likely to be exploited, and CVE-2026-72971, a publicly disclosed low-impact local tampering flaw.

    Show sources