CyberzSOC

Publication detail
← Back to advisories & guidance

Microsoft Releases August 2026 Security Updates ↗ source

August 12, 2026 JPCERT/CC Alert

Summary

Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication or elevate privileges locally after authentication, etc. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. Please refer to the latest information provided by Microsoft and implement the measures described in "II. Solution." Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Please apply the security update programs through Microsoft Update, Windows Update, etc. If you have any information regarding this alert, please contact JPCERT/CC.

News Coverage

DateSourceArticle
2026-08-17 Check Point Research 17th August – Threat Intelligence Report CVE-2026-68820
2026-08-12 BleepingComputer Lazarus hackers exploited Windows zero-day to target defense firms CVE-2026-68820
2026-08-11 SANS Internet Storm Center Microsoft Patch Tuesday August 2026, (Tue, Aug 11th) CVE-2026-68820
2026-08-11 The Hacker News Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack CVE-2026-68820
2026-08-11 Check Point Research Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack CVE-2026-68820

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-68820 7.0 High Microsoft Windows Ancillary Function Driver for WinSock Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privile…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.