HackMyIP
← Back to News
2026-08-11 The Hacker News

Microsoft Patches 398 Flaws Including Actively Exploited Windows Zero-Day

Zero-DayVulnerabilityAPT

Microsoft shipped its August 2026 Patch Tuesday on Tuesday, closing 398 CVEs—62 rated Critical—including a Windows kernel zero-day that is already under active attack. The Zero Day Initiative independently tallied the release at 398 new CVEs, but patch urgency is not a function of count; it is a function of exploit status and reach. With one bug being weaponized in the wild and four others that need nothing from the victim to take over a server, administrators have a clear ordering problem on their hands.

The actively exploited flaw, tracked as CVE-2026-68820 with a CVSS score of 7.0, is a use-after-free in afd.sys, the Ancillary Function Driver for WinSock—a kernel-side component of Windows networking. According to Check Point Research, the North Korea-linked Lazarus Group leveraged the bug in its Operation Dream Job campaign. The vulnerability is a privilege escalation: an attacker with code already running on a machine can trigger a race condition in the driver to escalate to SYSTEM. Microsoft has not publicly attributed the exploitation, but its Exploited status pushes this fix to the front of the queue, ahead of the 9.8-rated server bugs despite its lower score.

Trailing the driver bug in priority are four unauthenticated remote code execution flaws, all rated 9.8, affecting Windows DNS Server (CVE-2026-62878), Windows Deployment Services (CVE-2026-62893), Microsoft's QUIC transport implementation (CVE-2026-62815), and HPC Pack (CVE-2026-59124). The DNS Server flaw is a stack-based buffer overflow reachable remotely with no authentication and no user interaction, and ZDI flagged the condition as wormable—an important caveat given that DNS infrastructure often sits at the network edge. Teams running on-prem resolvers should validate exposure with a port scanner and confirm resolver behavior with a DNS leak test before applying the patch. The QUIC flaw hits Microsoft's modern transport stack, a useful reminder that even newer protocol implementations warrant scrutiny with an SSL/TLS checker. HPC Pack, while rated 9.8, is marked Important rather than Critical because it is not installed by default.

The release also closes the RCE half of a SharePoint exploit chain whose authentication bypass was patched in July—on-premises SharePoint farms need both updates installed to be fully protected. With 398 CVEs in a single drop, IT teams should treat this as a tiered rollout: install the exploited driver fix first, then the four unauthenticated 9.8 server RCEs, then complete the SharePoint pair.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →