SAN FRANCISCO — Microsoft released 421 security updates as part of its Aug. 2026 Patch Tuesday cycle, including a critical fix for CVE-2026-68820, a high-severity vulnerability already under active exploitation. The zero-day allows attackers to elevate privileges within affected systems without user interaction.

The flaw targets the Ancillary Function Driver for WinSock, known as afd.sys, a kernel-mode driver that serves as a core component of the Windows Sockets API. Attackers exploit a use-after-free issue to trigger a race condition, gaining SYSTEM privileges.

Microsoft did not disclose details about the observed attacks. Satnam Narang, a senior staff research engineer at Tenable, said nation-state threat actors may have exploited the vulnerability, an assessment consistent with historical tradecraft targeting afd.sys flaws.

The driver has been a repeated target for sophisticated actors. Since 2022, three other zero-days involving afd.sys have been exploited in the wild: CVE-2025-32709, CVE-2025-21418 and CVE-2024-38193. North Korean hackers linked to the Lazarus group reportedly exploited CVE-2024-38193.

Beyond the actively exploited zero-day, the August release addresses CVE-2026-62832, an improper link resolution flaw in the Windows User Profile Service. The publicly disclosed vulnerability allows an authenticated attacker to load another user's registry hive, potentially enabling access to or modification of user data and administrator privileges. Narang said threat actors are likely to begin exploiting CVE-2026-62832 given its public disclosure.

Another publicly disclosed issue, CVE-2026-72971, involves a link-following flaw in the Windows Container Isolation FS Filter Driver. Microsoft assessed that vulnerability as unlikely to be exploited in active attacks.

The August updates also resolve several remote code execution bugs: CVE-2026-62878 in Windows DNS Server, CVE-2026-62893 in Windows Deployment Services TFTP Server, CVE-2026-62815 in Microsoft QUIC and CVE-2026-59124 in Microsoft HPC Pack. An elevation of privilege bug, CVE-2026-62911, was also fixed in Exchange Server, Dustin Childs of ZDI said.

The patch scope spans numerous Microsoft products. Windows received 236 vulnerability fixes. Office and Office 2016 each received 98 fixes. SharePoint Server received 30 updates, Developer Tools 26 and Azure 17. Exchange Server addressed seven vulnerabilities, while Defender and other products received one and six fixes respectively.

The volume of critical patches—particularly those covering actively exploited flaws—imposes direct operational costs on enterprise IT departments, which must allocate staff and budget for immediate patching cycles, system audits and exposure assessments against nation-state and other sophisticated threat actors.