Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack


Microsoft has released a critical security update addressing 398 newly discovered vulnerabilities, including a Windows driver zero-day that is currently under active attack. The vulnerability, tracked as CVE-2026-68820, allows an attacker to escalate privileges from code running on a machine to SYSTEM level access.

  • Microsoft has released a security update addressing 398 newly discovered vulnerabilities.
  • A Windows driver zero-day vulnerability (CVE-2026-68820) is currently under active attack, allowing an attacker to escalate privileges to SYSTEM level access.
  • The vulnerability can be exploited without prior authorization or user interaction, posing a significant security risk.
  • 62 of the released vulnerabilities were rated critical, while only one (CVE-2026-68820) is under active exploitation.
  • The patching effort also includes fixes for other critical vulnerabilities in Windows DNS Server and Microsoft's QUIC transport protocol implementation.



  • Microsoft's latest security update has been released, addressing 398 newly discovered vulnerabilities, including a particularly concerning Windows driver zero-day that is currently under active attack. The patching effort was undertaken by Microsoft to ensure the security and stability of its operating systems.

    The newly disclosed vulnerability, tracked as CVE-2026-68820, is located in the afd.sys component of Windows networking, which serves as an ancillary function for WinSock. According to Check Point Research, this zero-day flaw represents a use-after-free bug that allows an attacker to escalate privileges from code running on a machine to SYSTEM level access.

    An attacker does not need any prior authorization or user interaction to exploit the vulnerability; all they must do is have already established code execution on their own system. This situation signifies a serious security risk for users, as having this kind of zero-day attack would allow an attacker to manipulate and control the affected machine with complete impunity.

    While Microsoft has flagged CVE-2026-68820 as being under active exploitation, no attribution has been given at this time, suggesting that it may be difficult for Microsoft to determine who is using or abusing this newly discovered vulnerability. Despite the fact that only 62 of the released vulnerabilities were rated critical, the impact of CVE-2026-68820 remains significant due to its ability to allow code execution and its potential risks.

    The patching effort also includes a number of other non-exploitable but critical security fixes for Windows DNS Server, Windows Deployment Services, Microsoft's QUIC transport protocol implementation, and HPC Pack. These vulnerabilities were all rated as having a CVSS score of 9.8, which signifies that they are particularly severe.

    In addition to the new patches, this month's release also completes a two-part SharePoint fix that began in July. The first component was patched in July, while the second part has been addressed in August. Rapid7 Labs reported an exploit chain for this vulnerability on May 18, and Microsoft later confirmed its intentions to address the issue by splitting the remediation into two separate updates.

    Microsoft's patch cycle is a vital tool for maintaining computer system security, ensuring that users receive regular updates that protect them from newly discovered vulnerabilities like CVE-2026-68820. It remains crucial for individuals and organizations alike to keep their systems up-to-date with the latest patches in order to minimize potential risks associated with using older operating systems or software.

    Furthermore, this month's release demonstrates how important it is to stay vigilant when it comes to cybersecurity; a single zero-day vulnerability can have devastating consequences if not addressed promptly. It highlights the need for constant vigilance and proactive measures to safeguard computer systems against such threats.

    In conclusion, the newly disclosed vulnerabilities represent an urgent reminder of the importance of ongoing security patches and the significance of staying up-to-date with the latest software updates.

    Microsoft has released a critical security update addressing 398 newly discovered vulnerabilities, including a Windows driver zero-day that is currently under active attack. The vulnerability, tracked as CVE-2026-68820, allows an attacker to escalate privileges from code running on a machine to SYSTEM level access.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Microsoft-Patches-398-Flaws-Including-a-Windows-Driver-Zero-Day-Under-Active-Attack-ehn.shtml

  • https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html

  • https://www.imtr.net/article/microsoft-patches-398-flaws-including-a-windows-driver-zero-day-under-active-e8cb


  • Published: Tue Aug 11 16:07:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us