[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day-msq3rf52":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":19,"article_ids":20,"ioc_summary":22,"source_urls":23,"status":25,"expires_at":26,"created_at":27,"updated_at":28,"articles":29},"71b25fff-c8c7-4315-a7ec-483cf604542f","August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day","august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day-msq3rf52","Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk of local privilege escalation.","critical","advisory",[12],"CVE-2026-68820",[14,15,16,17,18],"afd.sys","Windows Sockets API","Windows User Profile Service","Windows Container Isolation FS Filter Driver","Windows DNS server","Prioritize patching CVE-2026-68820 (afd.sys) on all Windows endpoints. Hunt for exploitation attempts by searching for unexpected afd.sys process interactions, kernel crashes, and lateral movement from standard user accounts to SYSTEM.",[21],"edc7720c-6e8c-4076-ba3e-e2ef3d058667",null,[24],"https:\u002F\u002Fwww.securityweek.com\u002Faugust-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day\u002F","archived","2026-08-14T13:05:48.157+00:00","2026-08-12T13:05:54.337613+00:00","2026-08-14T14:06:15.700835+00:00",[30],{"id":21,"title":6,"url":24}]