CVE-2026-68820

Published Aug 11, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-68820 is identified as a "Use after free" vulnerability found within the Windows Ancillary Function Driver for WinSock. This flaw enables an authorized attacker to achieve local privilege escalation. The vulnerability was recognized as a zero-day exploit and was actively leveraged in attacks. Microsoft addressed CVE-2026-68820 as part of its August 2026 Patch Tuesday release.

Description
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_11_26h1, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2025

Risk scores

CVSS 3.1

Type
Secondary
Base score
7
Impact score
5.9
Exploitability score
1
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Exploit added on
Aug 11, 2026
Exploit action due
Aug 25, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

secure@microsoft.com
CWE-416

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

  1. 🚨 NUEVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · explotación activa Afectados: Sistemas Windows com driver AFD.sys Use-after-free https://t.co/rkgrmP2emR

    @Douglas01284182

    13 Aug 2026

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 NOVA CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRÍTICO) · KEV 11/08/2026 · exploração ativa Afetados: Sistemas Windows com driver AFD.sys Use-after-free no W https://t.co/jmt6RHDBtT

    @Douglas01284182

    13 Aug 2026

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 NEW CVE: CVE-2026-68820 — Windows WinSock AFD (Use-After-Free LPE) ⚠️ CVSS 7.0 (CRITICAL) · KEV 11/08/2026 · active exploitation Affected: Sistemas Windows com driver AFD.sys Use-after-free n https://t.co/HS0KUGrIZY

    @Douglas01284182

    13 Aug 2026

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. "Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored ht

    @GHHILL1911

    13 Aug 2026

    242 Impressions

    1 Retweet

    6 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. 🚨 Last 24h is HOT — primary sources only CISA added 3 KEVs on 11 Aug (all actively exploited): • CVE-2026-20349 — Cisco ASA/FTD unauth SSL VPN DoS Official: https://t.co/InN3hhGaSD Fed deadline: 14 Aug. No workarounds. Hotfix now. • CVE-2026-68820 — Windows afd.sys L

    @seoscottsdale

    13 Aug 2026

    223 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  6. Lazarus is burning a Windows zero-day (CVE-2026-68820) against defense firms while SharePoint (CVE-2026-55040) falls to public PoC exploitation. #CyberSecurity #BlueTeam #ZeroDay https://t.co/1Fsc4x2SHo

    @itsalreadywhen

    13 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. 1/4 🚨 Last 24h cyber snapshot is HOT CISA just dropped 3 KEVs (Aug 11): Cisco ASA/FTD DoS (CVE-2026-20349), Windows AFD.sys LPE (CVE-2026-68820), Metabase unauth SQLi (CVE-2026-72898). Lazarus already weaponizing the Windows zero-day vs defense firms.

    @CipherWardenAI

    13 Aug 2026

    202 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    2 Replies

    1 Quote

  8. North Korean 🇰🇵 Lazarus Group weaponized a Windows zero-day (CVE-2026-68820) in Operation Dream Job, hitting defense and aerospace professionals in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳 with fake Lockheed Martin job offers. - CVE-2026-68820

    @DFIR_Radar

    13 Aug 2026

    199 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. Microsoft's August 2026 Patch Tuesday closed 3 zero-days (400+ CVEs total): - CVE-2026-68820 — AFD.sys (WinSock) — actively exploited - CVE-2026-62832 — Windows User Profile Service — publicly disclosed - CVE-2026-72971 — Container Isolation FS Filter Driver — public

    @tac0tech

    13 Aug 2026

    77 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Microsoft patched CVE-2026-68820 as part of August Patch Tuesday, a high severity bug in the Windows Ancillary Function Driver for WinSock already exploited in the wild. The flaw affects Windows 10 1607 to 22H2, Windows 11 23H2 to 26H1, and Windows Server 2012 to 2025, scored

    @NeowinFeed

    13 Aug 2026

    934 Impressions

    3 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  11. North Korea 🇰🇵's Lazarus group deployed a Windows kernel zero-day via a post-quantum encrypted channel against defense and aerospace firms in France 🇫🇷, Germany 🇩🇪, Brazil 🇧🇷, and India 🇮🇳, with a patch shipping August 11. - CVE-2026-68820 is a use-

    @DFIR_Radar

    12 Aug 2026

    228 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    2 Replies

    0 Quotes

  12. Active exploitation of VMware vCenter (CVE-2026-59310) and Cisco ASA/FTD (CVE-2026-20349), plus a Windows afd.sys zero-day (CVE-2026-68820) in this month's Patch Tuesday. #CyberSecurity #BlueTeam #ZeroDay https://t.co/8JN5RsqS06

    @itsalreadywhen

    12 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. 🛡️We added Cisco Secure Firewall vulnerability CVE-2026-20349, Microsoft Windows vulnerability CVE-2026-68820 & Metabase vulnerability CVE-2026-72898 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cyberse

    @CISACyber

    12 Aug 2026

    8537 Impressions

    7 Retweets

    18 Likes

    2 Bookmarks

    1 Reply

    0 Quotes

  14. Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820): Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and… https://t.co/DBkKoaPWYg

    @shah_sheikh

    12 Aug 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp

    @lee1981b

    12 Aug 2026

    109 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. 🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp

    @lee1981b

    12 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🔥 CyberForge CVE of the Day #022 🚨 CVE-2026-68820 — An actively exploited Windows Ancillary Function Driver for WinSock (afd.sys) use-after-free allows a low-privileged local attacker to elevate privileges through kernel memory corruption. ⭐ Vendor: Microsoft ⭐ Comp

    @lee1981b

    12 Aug 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. Operation Dream Job #Lazarus exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. https://t.co/A7xGb08NtE Lazarus also used CVE-2025-49113 to exploit vulnerable Roundcube

    @blackorbird

    12 Aug 2026

    2126 Impressions

    6 Retweets

    19 Likes

    5 Bookmarks

    1 Reply

    0 Quotes

  19. 北朝鮮系Lazarusが、偽の求人を使うOperation Dream Jobを再展開し、WindowsのゼロデイCVE-2026-68820を悪用して防衛・航空宇宙企業を侵害した。攻撃ではトロイ化PDFビューアや新型バックドア、カーネルルートキットも

    @yousukezan

    12 Aug 2026

    2479 Impressions

    0 Retweets

    13 Likes

    10 Bookmarks

    0 Replies

    0 Quotes

  20. 🚨 Microsoft August Patch Tuesday — 398+ CVEs, 3 Zero-Days CVE-2026-68820 — WinSock EoP (ACTIVE zero-day, Lazarus) CVE-2026-62878 — DNS Server RCE (9.8, wormable) CVE-2026-62893 — TFTP Server RCE (9.8, more likely) → https://t.co/vOC4TItXgB #cybersecurity #PatchTuesd

    @ThreatAft

    12 Aug 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Microsoft’s August Patch Tuesday addresses multiple critical vulnerabilities. Prioritise actively exploited CVE-2026-68820, alongside publicly disclosed CVE-2026-62832 and CVE-2026-72971. Review, test and patch promptly: https://t.co/01elXNUXLy #PatchTuesday #MSSP #SOC

    @FactoryInternet

    11 Aug 2026

    190 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝘂𝗴𝘂𝘀𝘁 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 August Patch Tuesday is here, and we have 𝟯 𝗻𝗲𝘄 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀 and 𝟲 vulnerabilities with a CVS

    @horizon_secured

    11 Aug 2026

    314 Impressions

    0 Retweets

    4 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  23. Microsoft's August Patch Tuesday fixed 400 flaws, including 3 Windows zero-days, all local privilege-escalation bugs needing no user interaction: • CVE-2026-68820: AFD.sys WinSock flaw, already exploited by Lazarus to deploy the FudModule rootkit • CVE-2026-62832: User Profi

    @XavierRiveraX

    11 Aug 2026

    92 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  24. 0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z

    @_CPResearch_

    11 Aug 2026

    8491 Impressions

    50 Retweets

    172 Likes

    69 Bookmarks

    2 Replies

    2 Quotes

  25. 0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2

    @_CPResearch_

    11 Aug 2026

    269 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 0-Day Used by Lazarus in #DreamJob Campaign Against Defense Sector: 💥LPE vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure Read More : https://t.co/GDI2Z

    @_CPResearch_

    11 Aug 2026

    265 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. 0-Day Used by Lazarus in the #DreamJob Campaign Against Defense Sector: 💥LPE via a vulnerability in Microsoft’s Afd.sys driver (#CVE-2026-68820) 🧰New tools, including the #Troy backdoor 🌍Compromised Roundcube servers (CVE-2025-49113) as infrastructure https://t.co/GDI

    @_CPResearch_

    11 Aug 2026

    381 Impressions

    1 Retweet

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations