AI description
CVE-2026-68820 is identified as a "Use after free" vulnerability found within the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to achieve local privilege escalation. The vulnerability was recognized as a zero-day exploit and was actively leveraged in attacks. Microsoft addressed CVE-2026-68820 as part of its August 2026 Patch Tuesday release.
- Description
- Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025
CVSS 3.1
- Type
- Secondary
- Base score
- 7
- Impact score
- 5.9
- Exploitability score
- 1
- Vector string
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
- Exploit added on
- Aug 11, 2026
- Exploit action due
- Aug 25, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- secure@microsoft.com
- CWE-416
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
🚨 NUEVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · explotación activa Afectados: Sistemas Windows com driver AFD.sys Use-after-free https://t.co/rkgrmP2emR
@Douglas01284182
13 Aug 2026
14 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NOVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · exploração ativa Afetados: Sistemas Windows com driver AFD.sys Use-after-free no W https://t.co/jmt6RHDBtT
@Douglas01284182
13 Aug 2026
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NEW CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRITICAL) · KEV 11/08/2026 · active exploitation Affected: Sistemas Windows com driver AFD.sys Use-after-free n https://t.co/HS0KUGrIZY
@Douglas01284182
13 Aug 2026
15 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
"Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored ht
@GHHILL1911
13 Aug 2026
242 Impressions
1 Retweet
6 Likes
0 Bookmarks
1 Reply
0 Quotes
🚨 Last 24h is HOT — primary sources only CISA added 3 KEVs on 11 Aug (all actively exploited): • CVE-2026-20349 — Cisco ASA/FTD unauth SSL VPN DoS Official: https://t.co/InN3hhGaSD Fed deadline: 14 Aug. No workarounds. Hotfix now. • CVE-2026-68820 — Windows afd.sys L
@seoscottsdale
13 Aug 2026
223 Impressions
0 Retweets
0 Likes
0 Bookmarks
2 Replies
0 Quotes
Lazarus is burning a Windows zero-day (CVE-2026-68820) against defense firms while SharePoint (CVE-2026-55040) falls to public PoC exploitation. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1Fsc4x2SHo
@itsalreadywhen
13 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.
@CipherWardenAI
13 Aug 2026
202 Impressions
1 Retweet
0 Likes
0 Bookmarks
2 Replies
1 Quote
North Korean 🇰🇵 Lazarus Group weaponized a Windows zero-day (CVE-2026-68820) in Operation Dream Job, hitting defense and aerospace professionals in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳 with fake Lockheed Martin job offers. - CVE-2026-68820
@DFIR_Radar
13 Aug 2026
199 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Microsoft's August 2026 Patch Tuesday closed 3 zero-days (400+ CVEs total): - CVE-2026-68820 — AFD.sys (WinSock) — actively exploited - CVE-2026-62832 — Windows User Profile Service — publicly disclosed - CVE-2026-72971 — Container Isolation FS Filter Driver — public
@tac0tech
13 Aug 2026
77 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored
@NeowinFeed
13 Aug 2026
934 Impressions
3 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
North Korea 🇰🇵's Lazarus group deployed a Windows kernel zero-day via a post-quantum encrypted channel against defense and aerospace firms in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳, with a patch shipping August 11. - CVE-2026-68820 is a use-
@DFIR_Radar
12 Aug 2026
228 Impressions
0 Retweets
2 Likes
0 Bookmarks
2 Replies
0 Quotes
Active exploitation of VMware vCenter (CVE-2026-59310) and Cisco ASA/FTD (CVE-2026-20349), plus a Windows afd.sys zero-day (CVE-2026-68820) in this month's Patch Tuesday. #CyberSecurity #BlueTeam #ZeroDay https://t.co/8JN5RsqS06
@itsalreadywhen
12 Aug 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse
@CISACyber
12 Aug 2026
8537 Impressions
7 Retweets
18 Likes
2 Bookmarks
1 Reply
0 Quotes
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820): Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and… https://t.co/DBkKoaPWYg
@shah_sheikh
12 Aug 2026
62 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp
@lee1981b
12 Aug 2026
109 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp
@lee1981b
12 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp
@lee1981b
12 Aug 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Operation Dream Job #Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. https://t.co/A7xGb08NtE Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube
@blackorbird
12 Aug 2026
2126 Impressions
6 Retweets
19 Likes
5 Bookmarks
1 Reply
0 Quotes
北朝鮮系Lazarusが、偽の求人を使うOperation Dream Jobを再展開し、WindowsのゼロデイCVE-2026-68820を悪用して防衛・航空宇宙企業を侵害した。攻撃ではトロイ化PDFビューアや新型バックドア、カーネルルートキットも
@yousukezan
12 Aug 2026
2479 Impressions
0 Retweets
13 Likes
10 Bookmarks
0 Replies
0 Quotes
🚨 Microsoft August Patch Tuesday — 398+ CVEs, 3 Zero-Days CVE-2026-68820 — WinSock EoP (ACTIVE zero-day, Lazarus) CVE-2026-62878 — DNS Server RCE (9.8, wormable) CVE-2026-62893 — TFTP Server RCE (9.8, more likely) → https://t.co/vOC4TItXgB #cybersecurity #PatchTuesd
@ThreatAft
12 Aug 2026
84 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Microsoft’s August Patch Tuesday addresses multiple critical vulnerabilities. Prioritise actively exploited CVE-2026-68820, alongside publicly disclosed CVE-2026-62832 and CVE-2026-72971. Review, test and patch promptly: https://t.co/01elXNUXLy #PatchTuesday #MSSP #SOC
@FactoryInternet
11 Aug 2026
190 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝘂𝗴𝘂𝘀𝘁 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 August Patch Tuesday is here, and we have 𝟯 𝗻𝗲𝘄 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀 and 𝟲 vulnerabilities with a CVS
@horizon_secured
11 Aug 2026
314 Impressions
0 Retweets
4 Likes
1 Bookmark
0 Replies
0 Quotes
Microsoft's August Patch Tuesday fixed 400 flaws, including 3 Windows zero-days, all local privilege-escalation bugs needing no user interaction: • CVE-2026-68820: AFD.sys WinSock flaw, already exploited by Lazarus to deploy the FudModule rootkit • CVE-2026-62832: User Profi
@XavierRiveraX
11 Aug 2026
92 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z
@_CPResearch_
11 Aug 2026
8491 Impressions
50 Retweets
172 Likes
69 Bookmarks
2 Replies
2 Quotes
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2
@_CPResearch_
11 Aug 2026
269 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z
@_CPResearch_
11 Aug 2026
265 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
0-Day Used by Lazarus in the #DreamJob Campaign Against Defense Sector: 💥LPE via a vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including the #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure https://t.co/GDI
@_CPResearch_
11 Aug 2026
381 Impressions
1 Retweet
5 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "14FF7EDA-F43B-4BB4-BC6C-7EFE15382EEB",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "CB3EDBCC-9F4E-49F2-9701-67D2C1F7B47A",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
"matchCriteriaId": "3B36E37E-C661-4F5B-BFAB-8DE7EA3BBF5A",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
"matchCriteriaId": "490C0819-7717-4869-B85C-2A218E7C50B2",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B27B392C-BA96-4CAA-8368-64DB0C90F204",
"versionEndExcluding": "10.0.19044.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "94D69542-4258-4423-9815-0191DE06A4E7",
"versionEndExcluding": "10.0.19045.7663",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "0821B99A-2DDC-4B1E-999A-76EC1D018CD5",
"versionEndExcluding": "10.0.22631.7517",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3539AA11-7E3B-4EBC-9427-C2F58A6BA963",
"versionEndExcluding": "10.0.26100.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "F25F821F-F56B-4150-80B7-9A6108FAA8BD",
"versionEndExcluding": "10.0.26200.9106",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:*:*",
"matchCriteriaId": "645B7F94-BBDA-41B1-825B-6103F2AC2FC9",
"versionEndExcluding": "10.0.28000.2704",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A7DF96F8-BA6A-4780-9CA3-F719B3F81074",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*",
"matchCriteriaId": "DB18C4CE-5917-401E-ACF7-2747084FD36E",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"matchCriteriaId": "14EEFCD3-C815-4CBE-99AB-6AFB40EF2FE9",
"versionEndExcluding": "10.0.14393.9418",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7877A816-4EF3-4DA9-81F6-DF77056F329B",
"versionEndExcluding": "10.0.17763.9115",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8EBC7E47-4744-4802-B04C-869AA63985A5",
"versionEndExcluding": "10.0.20348.5440",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "48C0EB1A-5EC0-4916-A812-08E16FEB040A",
"versionEndExcluding": "10.0.26100.33222",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]