HackMyIP
← Back to News
2026-08-11 KrebsOnSecurity

Microsoft Patches 398 Flaws Including Active Zero-Day in Windows afd.sys Driver

VulnerabilityZero-DayAI Security

Microsoft released its August Patch Tuesday bundle addressing nearly 400 security vulnerabilities across Windows and supported software, including one actively exploited zero-day and two others disclosed prior to today's release. While the 398 fixes did not eclipse last month's record-breaking batch of more than 570 security updates, they double June's then-record haul of nearly 200 patches. Of the total, 42 flaws earned Microsoft's most severe "critical" rating, meaning attackers could exploit them to gain remote control over a Windows machine with little or no user interaction. Microsoft has attributed the recent surge in disclosed vulnerabilities to artificial intelligence-assisted vulnerability discovery, a trend that now defines the modern Patch Tuesday cadence.

The sole actively exploited zero-day fixed this month is CVE-2026-68820, a privilege escalation flaw in afd.sys, the kernel driver that powers Windows socket connections on virtually every endpoint. Automox researcher Landon Miles described it as "step two in a chain" — an attacker first establishes a low-privilege foothold via phishing, then leverages the race condition in afd.sys to fully compromise the host. Despite a CVSS score of 7.0 reflecting the exploit's high attack complexity, Miles confirmed that "someone is clearly landing it anyway." Microsoft also flagged CVE-2026-62832, a Windows User Profile Service privilege escalation flaw likely linked to the recent "LegacyHive" disclosure from the prolific bug hunter known as Nightmare Eclipse. A third publicly known bug, CVE-2026-72971, is a low-impact local tampering vulnerability Microsoft considers unlikely to be weaponized. Windows administrators should prioritize endpoint patching immediately and verify exposed services with a port scanner to identify any sockets still listening on vulnerable afd.sys interfaces.

Microsoft is not alone in facing AI-driven patch inflation. Adobe recently moved to twice-monthly security bulletins, and Cisco, Google, Mozilla, and Oracle are all shipping updates far more frequently and abundantly. AI is demonstrably good at finding security holes, but patching the resulting flood remains a heavily human-centric endeavor. While AI tools are beginning to suggest fixes for the vulnerabilities they discover, researchers at 1Password have warned that the technology has not yet proven equally capable at remediating them as it is at exploiting them. For now, organizations must enforce disciplined patch management and harden user-facing attack surfaces. Security teams can reduce their overall exposure footprint by running a privacy checkup to identify leaking browser metadata, and by verifying employee credentials against a email breach checker to ensure that stolen credentials cannot be used to establish the initial phishing foothold described in the afd.sys exploit chain.

Source: KrebsOnSecurity →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →