Back to advisories

Lazarus hackers exploited Windows zero-day to target defense firms

Lazarus Group is actively exploiting Windows zero-day CVE-2026-68820 to target defense, aerospace, and aviation firms worldwide. The vulnerability enables privilege escalation to SYSTEM level and is being weaponized alongside a new backdoor called Troy. Compromised Roundcube instances have also been seeded with RelayShell PHP web shells for persistence.

CRITICALAdvisoryAug 14, 2026
Action required
Immediately scan all Windows systems for exploitation of CVE-2026-68820 and check for Troy backdoor artifacts and RelayShell web shells on Roundcube servers. Block known Lazarus IOCs and monitor defense/aerospace networks for lateral movement and C2 communications.
Affected products
Windows 11RoundcubeMicrosoftCheck Point