Microsoft patch includes zero-day actively exploited by North Korean attackers

Microsoft releases its August Patch Tuesday with over 400 fixes, notably addressing CVE-2026-68820, a zero-day flaw used in targeted attacks by North Korean hackers to escalate privileges and install malicious rootkits.

Microsoft’s August Patch Tuesday has landed with more than 400 fixes, but the headline issue is CVE-2026-68820, a zero-day flaw already being used in attacks. The bug affects the Windows Ancillary Function Driver for WinSock, or AFD.sys, and could let a low-privileged local attacker gain SYSTEM-level access. Microsoft said the flaw can be triggered by a specially crafted application and does not require user interaction, which makes it particularly worrying for organisations that assume local access is benign.

Security researchers at Check Point said North Korean attackers have been using the weakness to install a kernel-mode rootkit as part of a new wave of the Operation Dream Job campaign. That places the vulnerability in the same broader pattern of post-compromise tooling seen in targeted espionage operations, where privilege escalation is used to deepen access and conceal activity. Microsoft also patched three flaws that were publicly disclosed before the release, including CVE-2026-62832 in the Windows User Profile Service, CVE-2026-72971 in the Windows Container Isolation FS Filter Driver and CVE-2026-62737 in the Windows kernel.

The August release also includes defects with clear remote-code-execution potential. Microsoft’s QUIC issue, CVE-2026-62815, can reportedly be exploited over the network without authentication or user input, while CVE-2026-62878 in Windows DNS is a stack-based buffer overflow that can lead to remote code execution and is described as straightforward to exploit remotely. Rapid7 researchers also identified CVE-2026-63520 in SharePoint, which can be chained with a previously fixed bug to achieve unauthenticated remote code execution against a vulnerable server.

The scale of the update reinforces what several security vendors now describe as a new normal for Microsoft patching: large monthly batches, with only a subset demanding immediate action. Dustin Childs of Trend Zero Day Initiative said the rise in disclosed and fixed bugs has not yet been matched by a comparable increase in active exploitation, while Ivanti’s Chris Goettl urged teams to triage by exposure and risk rather than treating every high-CVSS issue as an emergency. Fortra’s Tyler Reguly added that administrators should not rush deployments without checking that updates are safe for their environments, a reminder that speed and stability now need to be balanced more carefully than ever.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.