www.cisa.gov 8/12/2026, 12:17:05 AM · external

CISA Flags Windows Driver Use After Free Flaw CVE-2026-68820

Developing story vulnerability 12 articles tracked
CISA adds Cisco firewall heap flaw CVE-2026-20349 to KEV catalog
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Listed in KEV
Patch Patch Available

THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as a vital resource for the cybersecurity community by detailing vulnerabilities exploited in the wild. Organizations are encouraged to utilize this catalog for prioritizing vulnerability management. A specific entry highlights a **use-after-free vulnerability** in the Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), allowing local privilege escalation.

Mitigation efforts should align with vendor instructions and CISA's guidelines, with an emphasis on patching based on risk. Users can view the KEV catalog in various formats and are invited to report any exploited vulnerabilities not included in the catalog.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline