/00 — boot sequence

Hello.

Article

Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Lazarus Zero-Day

August 12, 2026•6 min read
Patch Tuesday Windows Security Zero-Day Lazarus Group CVE-2026-68820 Privilege Escalation

Introduction

Microsoft shipped its August 2026 Patch Tuesday updates on August 11, fixing 400 vulnerabilities across Windows, Office, Exchange, .NET, and Azure services. Forty-two of those flaws are rated Critical, and 37 of the Critical bugs are remote code execution. The release also covers three zero-days: one has been actively exploited by the North Korean Lazarus group, and two were publicly disclosed before a fix existed.

If you run Windows endpoints, manage Exchange or SharePoint servers, or operate Azure workloads, this August 2026 Patch Tuesday deserves priority attention. The exploited bug, CVE-2026-68820, lives in the Windows Ancillary Function Driver for WinSock (afd.sys) and lets a local attacker reach SYSTEM privileges. Check Point Research ties it to Operation Dream Job, a Lazarus campaign that now targets defense contractors in Europe and India. This is the second time in two years that Lazarus has burned a zero-day in the same driver.

The Three Zero-Days

CVEComponentBug TypeStatus
CVE-2026-68820Ancillary Function Driver for WinSock (afd.sys)Use-after-free, local privilege escalation to SYSTEMActively exploited by Lazarus
CVE-2026-62832Windows User Profile ServiceLink-following privilege escalation (LegacyHive)Publicly disclosed
CVE-2026-72971Container Isolation FS Filter Driver (unionfs.sys)Link-following tamperingPublicly disclosed

CVE-2026-68820: Another afd.sys zero-day from Lazarus

Microsoft describes CVE-2026-68820 as a use-after-free in the Windows Ancillary Function Driver for WinSock that allows an authorized attacker to elevate privileges locally. A locally authenticated attacker runs a specially crafted application to trigger a race condition, and successful exploitation grants SYSTEM privileges. No user interaction is required. The find was credited to Moshe Marelus and David Driker of Check Point, who encountered the bug inside a FudModule sample.

FudModule is Lazarus's kernel-mode rootkit, in use since around 2021. The variant Check Point analyzed was compiled on July 7, 2026, and targets the same driver that carried CVE-2024-38193, an afd.sys use-after-free Lazarus exploited in 2024. The exploit performs an explicit minimum-version check for Windows 11 build 26100 (24H2), with support for build 26200 (25H2).

The mechanics are a classic race. afd.sys keeps a small piece of state per socket, and under concurrent access two of its code paths can operate on that state without synchronization. Triggered at the right moment, one path reads memory after another path has freed it, which yields a kernel read/write primitive. The module then escalates to SYSTEM and injects a payload into a system process, so the malware keeps running with EDR visibility disabled.

CVE-2026-62832: LegacyHive gets an official fix

The second zero-day is the Windows User Profile Service flaw known publicly as LegacyHive. Researcher Nightmare Eclipse disclosed it on July Patch Tuesday day with a stripped proof of concept. Tharros analyst Will Dormann showed that a non-admin user can modify another user's registry hive and get automatic code execution when that account logs in. Free unofficial patches appeared shortly after disclosure. Microsoft attributed this fix to an anonymous researcher, but the details match LegacyHive: an authenticated attacker with credentials for another local account can load that user's registry hive, access or modify their data, and gain administrator privileges. No user interaction is required.

CVE-2026-72971: unionfs.sys tampering

The third zero-day sits in the Windows Container Isolation FS Filter Driver (unionfs.sys), credited to yhw and txz. Microsoft describes it as improper link resolution before file access that allows local tampering. Details are thin, and the company has not said where the flaw was disclosed. If you run Windows containers or rely on unionfs for container file isolation, treat it as part of this month's must-patch set.

Why This Matters for Engineering Teams

Patch Tuesday volume keeps climbing, and Microsoft has said the growth is intentional: it now runs an AI-powered vulnerability discovery system that surfaces more flaws across its products. Last month's release fixed 570 vulnerabilities, this month's fixes 400, and neither count includes issues patched earlier in the month in Teams, Azure, Entra, Office, or Power Apps. Triage queues need a repeatable process, because the days of a manageable monthly Windows patch list are over.

For security teams the urgency is different. An APT with a kernel zero-day is not a hypothetical: Lazarus used CVE-2026-68820 in real intrusions to drop a rootkit that blinds EDR. That changes the risk conversation from "patch within 30 days" to "patch this week," at least for the endpoints that matter most.

Mitigation & Patching

  1. Install the August 2026 security updates now, and treat CVE-2026-68820 as urgent because it is under active exploitation.
  2. Deploy through Windows Update, WSUS, or Intune, and reboot afterwards. Driver fixes only take effect once the new afd.sys is loaded.
  3. Prioritize internet-facing servers: Exchange, SharePoint, DNS, and DHCP carry multiple Critical fixes this month, including RCE bugs in Exchange, Windows DNS Server, and DHCP Server.
  4. Remind staff about recruiters who push downloads. Operation Dream Job relies on fake job offers, and the new wave adds trojanized PDF viewers distributed through SEO-poisoned impersonation websites.
  5. If you cannot patch immediately, review the exchange of commands and keep EDR alerts loud for processes spawning from PDF viewers.

Detection

  • Look for child processes spawned from PDF viewers, especially anything writing new.exe under %TEMP%.
  • Monitor for unusual Microsoft Graph API traffic. MISTPEN, the downloader in this campaign, pulls modules from attacker-controlled OneDrive files.
  • Watch for kernel-mode driver loads after a job-interview themed phishing email. FudModule injects into SYSTEM processes and tries to disable EDR visibility, which often shows up as a sudden gap in telemetry.
  • For LegacyHive, audit registry hive manipulations involving the classes hive on multi-user machines, and treat unauthorized hive mounts as suspicious.

Frequently Asked Questions

Can CVE-2026-68820 be exploited remotely?

No. It is a local privilege escalation. Attackers chain it after initial access, typically gained through phishing, to move from a normal user to SYSTEM.

Which Windows versions are affected?

All supported Windows versions receive the August security updates. The analyzed exploit specifically targets Windows 11 24H2 (build 26100) and 25H2 (build 26200), but apply the updates everywhere they are offered.

Should I worry about LegacyHive if machines are single-user?

The bar is meaningful: an attacker needs credentials for another local account on the same machine. Shared workstations and lab machines are the realistic exposure, and the official fix is now available.

What is Operation Dream Job?

It is a long-running Lazarus campaign built around fake job offers at defense, aerospace, and aviation companies. The current wave uses two infection chains: DLL sideloading with a malicious libmupdf.dll, and a trojanized MuPDF-based viewer called SecurityPDF that decrypts a payload from crafted PDF files. The backdoors are MISTPEN, Troy, and ForestTiger, with FudModule for privilege escalation.

Will Patch Tuesday keep getting bigger?

Microsoft has said its AI-driven vulnerability discovery is a deliberate push to find more flaws. Expect similar or larger release volumes in coming months and plan your change management accordingly.

Key Takeaways

  • August 2026 Patch Tuesday ships fixes for 400 flaws, with 42 rated Critical.
  • CVE-2026-68820 is an afd.sys use-after-free exploited in the wild by Lazarus to deploy the FudModule rootkit and reach SYSTEM.
  • LegacyHive (CVE-2026-62832) and a unionfs.sys tampering bug (CVE-2026-72971) round out the zero-day count.
  • Treat the exploited bug as patch-this-week, not patch-this-month, and brief users on job-offer lures before the next intrusion attempt.

Sources: BleepingComputer, Check Point Research, BleepingComputer on LegacyHive

Automated Transmission

This entry was synthesized and populated dynamically using native API integrations.

Resources & Links