www.securityweek.com 8/11/2026, 6:58:05 PM · external

Microsoft Patch Tuesday Fixes Zero Day Winsock Flaw CVE-2026-68820

Microsoft Patch Tuesday Fixes Zero Day Winsock Flaw CVE-2026-68820
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CISA KEV Not in KEV
Patch Patch Available

MICROSOFT'S August 2026 Patch Tuesday addressed 421 CVEs, including a high-severity zero-day vulnerability (CVE-2026-68820) in WinSock's Ancillary Function Driver, allowing privilege escalation without user interaction. Other noteworthy vulnerabilities include CVE-2026-62832, which permits local privilege elevation via improper link resolution in the User Profile Service, and CVE-2026-72971 in Windows Container Isolation.

In total, the updates remediate 236 vulnerabilities in Windows, 98 in Office, and several in other products. Microsoft has indicated that some flaws may be targeted by threat actors, especially given the history of exploitation related to afd.sys vulnerabilities.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline