CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities catalogue. The flaw affects Microsoft’s Windows Ancillary Function Driver for WinSock and is identified as the Microsoft Windows Ancillary Function Driver for WinSock Use‑After‑Free Vulnerability. It allows an authorised local attacker to trigger a use‑after‑free condition and escalate privileges on the system.
The vulnerability is a classic use‑after‑free memory corruption issue in the WinSock ancillary function driver. Exploitation requires the attacker to have local access and valid credentials, after which they can execute arbitrary code with elevated privileges. The CVSS v3.1 score is 7.0, rated HIGH. Microsoft has released a patch that addresses the issue, and advisory details are available through the MSRC update guide.
Because the entry appears in the KEV catalogue, CISA confirms that the vulnerability is being actively exploited in the wild. No public reports link this flaw to ransomware campaigns at this time. Federal agencies must apply the required mitigations by the remediation due date of 25 August 2026.
CISA’s required action is to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s ‘Forensics Triage Requirements’. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. While the directive bind FCEB agencies, all organisations should review their Windows systems for exposure and prioritise applying the available patch.
For full technical details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-68820 and the CISA KEV catalogue.