Microsoft fixes 398 CVEs, led by exploited Windows driver flaw

Microsoft’s August security updates address 398 newly disclosed CVEs, including CVE-2026-68820, an actively exploited privilege-escalation flaw in a core Windows networking driver. The vulnerability has a CVSS score of 7.0, but Microsoft identifies it as the only issue in this month’s release under active exploitation.
CVE-2026-68820 affects afd.sys, the Ancillary Function Driver for WinSock. Check Point Research described the issue as a use-after-free vulnerability. An attacker must first have code running on the affected machine, then can exploit a race condition to elevate privileges to SYSTEM.
Microsoft has not publicly attributed the activity. Check Point Research said Lazarus used the zero-day in its Operation Dream Job campaign. The active exploitation status gives the driver bug higher operational priority than vulnerabilities with higher severity scores but no reported exploitation.
Four unauthenticated RCE flaws require service review
Four vulnerabilities carry CVSS scores of 9.8 and can be exploited remotely without an account, password, user interaction or click. They affect Windows DNS Server, Windows Deployment Services, Microsoft’s QUIC implementation and High Performance Computing Pack.
- CVE-2026-62878 is a stack-based buffer overflow in Windows DNS Server. The Zero Day Initiative described the condition as wormable, while noting that this technical label does not mean a worm exists.
- CVE-2026-62893 affects Windows Deployment Services through its TFTP handling.
- CVE-2026-62815 affects Microsoft QUIC.
- CVE-2026-59124 affects HPC Pack, which is not installed by default and is rated Important rather than Critical.
None of these four RCE flaws was marked as exploited when the updates shipped. Their practical urgency depends on whether the relevant service is installed, exposed and reachable. The release total underscores the need to distinguish volume from immediate exposure, as seen in ClickFix chains and AI-agent incidents’s account of ClickFix chains and AI-agent incidents, where an attack path can matter more than a headline count.
August update completes SharePoint chain remediation
The release also fixes CVE-2026-63520, the remote-code-execution component of an on-premises SharePoint exploit chain reported by Rapid7 Labs on May 18. Microsoft split remediation across its July and August update cycles.
July addressed CVE-2026-55040, a Critical authentication-bypass vulnerability scored at 9.1. Rapid7 said it could allow a remote unauthenticated attacker to impersonate a known SharePoint site user or administrator. When combined with the RCE component, the two issues produced unauthenticated RCE.
Rapid7 said applying the July update breaks the demonstrated chain, while the August update closes the remaining RCE component. Security teams should patch CVE-2026-68820 first on Windows systems, assess exposure to DNS, WDS, QUIC and HPC services, and confirm that on-premises SharePoint farms have both the July and August updates installed.

