securityaffairs.com 8/12/2026, 7:31:00 AM · external

Microsoft patches wormable DNS flaw and critical WinSock zero day

Microsoft patches wormable DNS flaw and critical WinSock zero day
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CISA KEV Listed in KEV
Patch Patch Available

MICROSOFT'S August 2026 Patch Tuesday update addresses 398 CVEs, including a zero-day vulnerability (CVE-2026-68820) and a wormable flaw (CVE-2026-62878) in Windows DNS Server. CVE-2026-68820 is a critical use-after-free bug in the WinSock driver that can allow code execution with SYSTEM-level privileges. CVE-2026-62878 allows remote, unauthenticated attackers to execute code with elevated privileges, necessitating immediate patching.

Other critical vulnerabilities relate to Windows Deployment Services and Microsoft's QUIC protocol. The update includes fixes for elevation of privileges vulnerabilities on Exchange servers and various other components.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline