Cookie Consent by Free Privacy Policy Generator

Microsoft addresses 421 vulnerabilities in August Patch Tuesday including actively exploited zero-day

Microsoft has released its August 2026 Patch Tuesday updates, addressing 421 CVEs across Windows and supported software. The patches include one zero-day vulnerability, CVE-2026-68820, which is already being exploited in the wild. The vulnerability is a use-after-free flaw in the afd.sys Windows kernel-mode driver that handles network socket operations. An attacker who has already gained code execution on a system can exploit this flaw to escalate privileges to SYSTEM level. North Korean threat actors have already been observed attacking this vulnerability, and the scale of this month's release continues the pattern of very large patch volumes that have become the norm for Microsoft's monthly security updates.

Why this matters for UK organisations

The operational challenge for UK IT teams is not just the presence of an actively exploited zero-day, but the sheer volume of vulnerabilities requiring assessment and prioritisation. 421 CVEs in a single month is a significant workload for any organisation, and the reality is that most IT teams cannot test and deploy every patch immediately. The actively exploited kernel driver vulnerability should be prioritised, particularly for systems that are accessible to users who may already be compromised or where privilege escalation would have significant impact. Organisations also need to consider the two other vulnerabilities that were publicly disclosed before patches became available, as public knowledge typically accelerates exploitation timelines. The fact that nation-state actors are already exploiting CVE-2026-68820 suggests that the vulnerability is being used in targeted campaigns, though the privilege escalation nature of the flaw means it requires prior access to be useful, making it most relevant in environments where initial compromise has already occurred or where insider threat is a concern.

What to review

Organisations should review their patch management prioritisation frameworks to ensure they can handle this volume of updates in a realistic timeframe. Focus initial efforts on CVE-2026-68820, particularly on systems exposed to untrusted users, endpoints used by privileged accounts, and any environments where privilege escalation would enable lateral movement to sensitive data or critical systems. It is also worth reviewing whether your organisation has clear visibility of which systems are running vulnerable versions of the afd.sys driver, and whether you have the monitoring in place to detect privilege escalation attempts. For organisations that cannot patch immediately, consider whether additional monitoring, network segmentation or access controls can reduce the window of exposure while patches are being tested and deployed. The scale of this month's release is a reminder that patch management is not just a technical process but an operational discipline that requires clear ownership, realistic timelines and the ability to make risk-based decisions about what to prioritise when everything cannot be done at once.

Source: SecurityWeek

News and blog posts
The Gunra ransomware gang, operating as a ransomware-as-a-service model, has...
Today's brief highlights the practical side of operational technology security,...
The NCSC has published new guidance specifically for the water sector, adding a...
Microsoft has released its August 2026 Patch Tuesday updates, addressing 421...