logo

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

ID: 0151f823-1677-5d55-9a55-aec544ef5c9f

STIX ID: report--0151f823-1677-5d55-9a55-aec544ef5c9f

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-08-12

Date Updated: 2026-08-12

Author: Zeljka Zorz

...
...

Microsoft's August 2026 Patch Tuesday fixed 400+ vulnerabilities, notably CVE-2026-68820 — a Windows AFD.sys use-after-free that has been exploited by North Korean actors as part of the Operation Dream Job campaign to deploy a kernel-mode rootkit — plus several publicly disclosed critical flaws and unauthenticated remote code execution vulnerabilities; the report also notes a proof-of-concept that bypasses a recent Microsoft Defender patch and advises cautious, triaged patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.