It’s not just Google that has a problem with use-after-free memory vulnerabilities; Microsoft has released a patch for such a zero-day issue that is already being exploited in the wild by attackers to deploy malware used by the North Korean hacking group known as Lazarus. CVE-2026-68820, the security vulnerability in question, sits in the WinSock ancillary function driver for WinSock. The high-rated vulnerability, that Microsoft said “allows an authorized attacker to elevate privileges locally” and gain system privileges, was disclosed by Check Point Research after observing it being used to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit.
Given that exploits are already being tracked, with the Cybersecurity and Infrastructure Security Agency adding CVE-2026-68820 to its Known Exploited Vulnerabilities database on August 11, users are advised to prioritize patching this issue.
Microsoft Fixes 421 Vulnerabilities With August 2026 Patch Tuesday Security Update
Microsoft has not bucked the trend of disclosing and patching large numbers of vulnerabilities in regular security updates that has been evident across vendors such as Google and Oracle this year so far. The August 2026 Patch Tuesday update has covered no less than 421 vulnerabilities in all, including three zero-days, of which CVE-2026-68820 is the only one listed as already being confirmed exploited.
Mike Walters, co-founder of Action1, has warned that a locally authenticated attacker with low privileges could “run a specially crafted application and trigger a race condition,” leading to privilege escalation and the potential to obtain “extensive control over the affected Windows system.” Which is why the confidentiality, integrity, and availability impacts of CVE-2026-68820 are all rated High. Deployment of the update patch “should be prioritized even though the vulnerability is rated important rather than critical,” as a result, Walters concluded.
“The ebb and flow of the ‘Patch Apocalypse’ continues with no sign of slowing yet,” Todd Schell, principal product manager at Ivanti, said. The problem is that not all Common Vulnerabilities and Exposures are created equal. “The patches need to be triaged to identify those CVEs that require immediate attention, including those tied to known exploitation or disclosure, known malware, CISA’s KEV list, or internet-facing or unauthenticated vulnerabilities,” Schell warned, but you need to remain disciplined and remember even CVEs with high CVSS scores which are not exploited or are not internet-facing can be handled in a second round of patching.” CVE-2026-68820 should, therefore, be on your priority list if you are a user of the impacted platforms. And that list is long: Microsoft Windows 10, Windows 11, Windows Server 2012, 2016, 2019, 2022 and 2025.







