> ## Content Index
> Fetch the complete content index at: https://www.thecybersignal.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Microsoft's August 2026 Patch Tuesday: 421 CVEs and an Actively Exploited afd.sys Zero-Day
- URL: https://www.thecybersignal.com/microsoft-patch-tuesday-august-2026-421-cves-afd-sys-zero-day/
- Published: 2026-08-11T12:40:00.000Z
- Updated: 2026-08-29T16:22:02.000Z
- Description: Microsoft's August 2026 Patch Tuesday is one of the largest on record: 421 CVEs by Rapid7's count, 62 rated critical, and a use-after-free in the afd.sys kernel driver that North Korea's Lazarus group used as a zero-day to reach SYSTEM. Patch that one first.
- Author: Nicholas Robert
- Tags: Vulnerabilities, Patch Management, Nation-State Cyber Threats

Microsoft's [August 2026 Patch Tuesday](https://www.rapid7.com/blog/post/em-patch-tuesday-august-2026/?ref=thecybersignal.com) is one of the heaviest single releases the company has ever shipped, and buried in it is the part that actually changes your week: a Windows kernel driver flaw that attackers were already using before the patch existed.

Microsoft's August 2026 Patch Tuesday shipped 421 CVEs (per [Rapid7](https://www.rapid7.com/blog/post/em-patch-tuesday-august-2026/?ref=thecybersignal.com) and [SecurityWeek](https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/?ref=thecybersignal.com); [SANS ISC](https://isc.sans.edu/diary/rss/33236?ref=thecybersignal.com) counts 418 and [Krebs](https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/?ref=thecybersignal.com) counts 398), 62 of them rated critical, and exactly one — `CVE-2026-68820`, a use-after-free in the `afd.sys` kernel driver — is already being exploited to escalate to SYSTEM. That single [vulnerability](https://www.thecybersignal.com/what-is-a-vulnerability-in-cybersecurity/), not the headline total, sets your patch order.

## The One That's Already Being Used

`CVE-2026-68820` is an elevation-of-privilege flaw carrying a CVSS score of 7.0 — a middling number that undersells it. It lives in `afd.sys`, the Ancillary Function Driver for WinSock, which is the kernel-mode plumbing behind the Windows Sockets API. The bug is a use-after-free triggered during network socket operations: an attacker who already has code running on the machine can race the driver into reusing freed memory and, from there, elevate a normal process to SYSTEM.

The defender translation is simple. This is not an entry point. An attacker needs a foothold first — a phished credential, a malicious document, a compromised app. What the flaw provides is the second step, the one that turns a limited user session into full control of the host. That is precisely the step that lets transient access become persistent, kernel-level access. [Microsoft's advisory](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68820?ref=thecybersignal.com) confirms in-the-wild exploitation, which is the only signal that should matter for sequencing your rollout this month.

afd.sys has a history here. It is a recurring target for privilege-escalation exploits precisely because it is loaded, network-adjacent, and reachable from low-privileged code. Treating a fresh `afd.sys` [zero-day](https://www.thecybersignal.com/what-is-a-zero-day-vulnerability/) as urgent is a pattern worth keeping.

## The Nation-State Angle

[The Register](https://www.theregister.com/security/2026/08/11/421-bugs-in-microsofts-patch-tuesday-release-and-the-norks-have-already-attacked-one/5286483?ref=thecybersignal.com) tied the exploited zero-day to DPRK-linked activity — "the Norks," in its phrasing. The brief for this piece flagged the specific North Korean cluster as unconfirmed, but the live reporting has since firmed up: in [a report published alongside the patches](https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/?ref=thecybersignal.com), Check Point attributes the exploitation of `CVE-2026-68820` to the Lazarus group and says the actors used it to deploy a new version of FudModule, Lazarus's kernel-mode rootkit, after luring a target with a fake job offer.

Two caveats belong on that attribution. It comes from one vendor's incident reporting, not from Microsoft, which has not named a threat actor. And no victims have been publicly identified. The through-line that survives the uncertainty is the tradecraft: a nation-state actor pairing a social-engineering foothold with a kernel EoP to install a rootkit is a well-worn playbook, and it is the reason a 7.0 gets treated like a far higher number.

## Two Publicly Disclosed, Not Yet Exploited

Alongside the exploited flaw, Microsoft fixed two elevation-of-privilege issues that were publicly disclosed before a patch shipped — meaning the details were already circulating, which shortens the runway to weaponization even though no exploitation has been observed yet.

| CVE            | Component                                                  | Type                          | CVSS | Status             |
| -------------- | ---------------------------------------------------------- | ----------------------------- | ---- | ------------------ |
| CVE-2026-68820 | afd.sys (Ancillary Function Driver for WinSock)            | Use-after-free, EoP to SYSTEM | 7.0  | Actively exploited |
| CVE-2026-62832 | Windows User Profile Service                               | Elevation of privilege        | 7.8  | Publicly disclosed |
| CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) | Tampering                     | —    | Publicly disclosed |

[CVE-2026-62832](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832?ref=thecybersignal.com) is an elevation-of-privilege flaw in the Windows User Profile Service that yields administrator rights on the local machine; [The Hacker News](https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html?ref=thecybersignal.com) notes the disclosed details line up with a researcher-published issue circulating last month. [CVE-2026-72971](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971?ref=thecybersignal.com) is a tampering flaw in the Windows Container Isolation FS Filter Driver, `unionfs.sys`. Neither has been seen in attacks, but public disclosure is exactly the condition that lets a proof-of-concept mature into a working exploit quickly.

## The Rest of the Release

Set the three zero-days aside and this is still a very large month. [Talos](https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/?ref=thecybersignal.com) and SANS ISC both count 62 vulnerabilities marked critical, and Rapid7 puts 236 of the fixes in Windows itself. The spread in the top-line total — 421 versus 418 versus 398 — is not a contradiction; it comes from how each outlet counts bundled browser (Chromium/Edge) and dependency CVEs, so pick one methodology and stay consistent rather than chasing the biggest number.

The critical-rated bucket is where remote code execution tends to concentrate, and those are the flaws to rank by exposure the way any [vulnerability management](https://www.thecybersignal.com/vulnerability-management-the-complete-guide/) programme would: internet-facing services first, then widely deployed internal software, then everything else. But none of the 62 critical flaws has known exploitation, and one 7.0 does — which is why severity score alone is the wrong sort order this month.

## Patch Priority, in Order

Roll It Out Top to Bottom

● 1\. Patch First — The Exploited Zero-Day

`CVE-2026-68820`, the `afd.sys` use-after-free (CVSS 7.0). Actively exploited to reach SYSTEM, DPRK-linked per Check Point. Deploy ahead of everything else.

2\. Then The Two Publicly Disclosed

`CVE-2026-62832` (User Profile Service) and `CVE-2026-72971` (`unionfs.sys`). Details already public; short runway to a working exploit.

3\. Then The 62 Critical, By Exposure

Rank the critical-rated RCE flaws by attack surface: internet-facing first, then widely deployed internal software.

4\. Then The Remaining Balance

The rest of the 400-plus CVEs, including the 236 Windows fixes, through your normal maintenance windows.

**My read:** the 421 headline is the wrong thing to react to. The number that should drive action is one: a CVSS 7.0 that a nation-state actor was already using to install a rootkit. Severity scores describe worst-case theory; a confirmed in-the-wild flag describes what is happening now, and this month those two signals point at different CVEs. Sort by the second one. The publicly disclosed pair is the near-term watch list — disclosure without a patch is the exact window where researchers and criminals build the exploit that did not exist yesterday. Everything else is a volume problem, and volume problems get solved by exposure-based ranking, not by starting at the top of an alphabetical list.

## What to Verify

Confirm your rollout against [Microsoft's Security Update Guide](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68820?ref=thecybersignal.com) rather than any single summary, since the counts differ by source. As of publication, `CVE-2026-68820` had not yet appeared in [CISA's Known Exploited Vulnerabilities catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?ref=thecybersignal.com) — but given Microsoft's confirmation of active exploitation, a KEV listing (and the federal remediation deadline that comes with it) is a reasonable expectation in the days ahead. Watch that catalog and treat the afd.sys fix as already past due regardless.

This release lands in a run of high-severity, exploited-in-the-wild flaws we have tracked recently — from [Cisco's dozen Catalyst SD-WAN and IOS XE flaws rated up to CVSS 9.9](https://www.thecybersignal.com/cisco-12-sd-wan-ios-xe-cvss-9-9-2026/) to [the Progress Kemp LoadMaster flaw that CISA added to KEV after nearly 800 exploit attempts](https://www.thecybersignal.com/progress-kemp-loadmaster-cve-2026-8037-kev-2026/). The common thread is the same each time: the vendor's severity label and the exploitation reality are two different inputs, and defenders who patch by the second one stay ahead.

## Primary Documents

- [Microsoft Security Response Center — CVE-2026-68820 advisory (afd.sys)](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68820?ref=thecybersignal.com)
- [Microsoft Security Response Center — CVE-2026-62832 (Windows User Profile Service)](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832?ref=thecybersignal.com)
- [Microsoft Security Response Center — CVE-2026-72971 (unionfs.sys)](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971?ref=thecybersignal.com)
- [Check Point Research — exploitation of CVE-2026-68820 by Lazarus](https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/?ref=thecybersignal.com)
- [Rapid7 — Patch Tuesday, August 2026](https://www.rapid7.com/blog/post/em-patch-tuesday-august-2026/?ref=thecybersignal.com)
- [Cisco Talos — Microsoft Patch Tuesday for August 2026](https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/?ref=thecybersignal.com)
- [SANS Internet Storm Center — Microsoft Patch Tuesday August 2026](https://isc.sans.edu/diary/rss/33236?ref=thecybersignal.com)
- [SecurityWeek — Microsoft Fixes 421 CVEs, One Exploited Zero-Day](https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/?ref=thecybersignal.com)
- [Krebs on Security — Microsoft Plugs Nearly 400 Security Holes](https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/?ref=thecybersignal.com)
- [CISA — Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?ref=thecybersignal.com)