CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
ID: 79aeaed2-29ba-5ba4-aa7e-76dfbfbf0e91
STIX ID: report--79aeaed2-29ba-5ba4-aa7e-76dfbfbf0e91
Feed Name: Qualys Blog
CVE-2026-68820 is an actively exploited use-after-free vulnerability in the Windows afd.sys driver (CVSS 7.0) that allows low-privileged local attackers to escalate to SYSTEM; CISA placed it in the KEV catalog with tight remediation deadlines under BOD 26-04 (3 days for internet-exposed systems, 14 days for internal systems). Microsoft released fixes in the August cumulative updates (KB5121003 for Windows 11 and KB5120249 for Windows 10 ESU), but because the fix replaces a kernel driver endpoints remain vulnerable until they are rebooted; the report urges immediate deployment and enforced reboots and promotes Qualys TruRisk Eliminate to automate deployment, reboot enforcement, and remediation verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
