Skip to content
Wednesday, October 7, 2026
iInnovate MagSTARTUPS · INNOVATION · GADGETS · AI
Tech News

Microsoft Patches 421 CVEs as One Zero-Day Is Exploited in the Wild

Microsoft's August 2026 Patch Tuesday closed 421 vulnerabilities, including one flaw already exploited in the wild. According to SecurityWeek's August 11, 2026 report , the exploited bug, CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock that lets a local…

Daniel Brooks · August 17, 2026 · 3 min read
ShareXFacebookLinkedInTelegramEmail
A system administrator's hands cross two patch queues on an off-white screen in a dim graphite server room, one warm orange progress bar the frame's single accent.
A system administrator's hands cross two patch queues on an off-white screen in a dim graphite server room, one warm orange progress bar the frame's single accent.

Microsoft's August 2026 Patch Tuesday closed 421 vulnerabilities, including one flaw already exploited in the wild. According to SecurityWeek's August 11, 2026 report, the exploited bug, CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock that lets a local attacker gain SYSTEM privileges.

What do the numbers actually say?

Counts vary with methodology, and the two main trackers published both. SecurityWeek, citing Microsoft's release, reports 421 CVEs patched. The Zero Day Initiative's monthly review by Dustin Childs, also published August 11, counts 398 new Microsoft CVEs and states 62 are rated Critical, one Moderate, and the rest Important. The ZDI review also notes the release spans Windows components, Office, Azure, GitHub Copilot, Exchange Server, SharePoint, DNS Server, and the Windows TPM.

The single bright spot, in ZDI's dry phrasing, is that there is only one CVE listed as under active attack this month. That bug aside, ZDI observes the bug volume itself has become routine — this volume of updates seems to be the new normal, the review states, even as reported exploitation has not grown proportionally. For security teams, that combination — a steady flood of fixes with rare active exploitation — argues for fast triage of the exploited item and steady, automated rollout of everything else.

Which flaw matters most, and why?

CVE-2026-68820, and the reason is elevation, not reach. SecurityWeek describes it as a use-after-free issue in afd.sys, the kernel-mode driver functioning as the backbone of the Windows Sockets API. Exploitation requires local authentication, and user interaction is not required, per Microsoft's advisory as quoted by SecurityWeek: a locally authenticated attacker running a crafted application to trigger a race condition could gain SYSTEM privileges.

In practice, that is the classic second-stage payload. Attackers who already have a foothold — a phished account, a malware dropper — use elevation bugs like this one to take full control of the machine. ZDI flags the flaw as rated Important with CVSS 7 and notes attackers can reach SYSTEM-level code execution through it, questioning the severity math in the process. Ratings aside, an exploited-in-the-wild label from the vendor itself removes any doubt about prioritization.

What should IT teams do with this release?

Patch on the normal cycle, but sequence by exposure. The priority list writes itself from the trackers' findings:

  1. Deploy the CVE-2026-68820 fix everywhere first — it is the one documented as exploited in the wild.
  2. Review internet-facing Exchange, SharePoint, and DNS servers next; ZDI highlights a wormable DNS Server remote code execution flaw, CVE-2026-62878, rated CVSS 9.8, though it is not listed as exploited.
  3. Work through the 62 Critical-rated CVEs in the ZDI count across workstations and server fleets.
  4. Reconcile the 421-versus-398 count difference in internal reporting — trackers count non-Windows and Edge CVEs differently — so dashboards do not contradict each other.

The next Patch Tuesday falls on September 8, 2026, per the ZDI review, which gives teams a four-week window before the cycle repeats at what has become its established volume.

iInnovate Mag is an independent publication and is not affiliated with any company mentioned in this article.

Sources

  1. August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day — SecurityWeek
  2. The August 2026 Security Update Review — Zero Day Initiative

More from our brands

Part of the VUGA Network