Microsoft’s August 2026 Patch Tuesday fixed 421 vulnerabilities, and one of them was already being used in attacks before the update shipped. If your office runs Windows 10, Windows 11, or Windows Server, that single flaw is the one to check off first this week.
- Microsoft’s August 2026 Patch Tuesday addressed 421 CVEs, including three zero-days.
- One flaw, CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock, was confirmed as actively exploited ahead of the patch.
- Researchers at Check Point tied exploitation to the North Korea-linked Lazarus group.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog, which is the government’s short list of bugs it expects every agency to patch fast.
- Affected versions stretch back to older Windows Server builds, a reminder for any Boston office still running Windows Server 2016.
What is CVE-2026-68820?
CVE-2026-68820 is a use-after-free bug in AFD.sys, the kernel driver that handles Windows networking sockets. A low-privileged attacker who already has a foothold on a machine, through malware, a phishing download, or a compromised account, can trigger a race condition in that driver and jump straight to SYSTEM privileges. Once an attacker has SYSTEM access, they can disable security tools, install additional malware, or move to other machines on the network. Microsoft rates it important with a CVSS score of 7.0, but active exploitation is what really raises the stakes.
Why does one CVE out of 421 matter more than the rest?
Most months, patch prioritization comes down to CVSS scores and whether a fix touches internet-facing services. This month is different because CVE-2026-68820 was already in use against real targets before Microsoft’s fix existed. That is the definition of a zero-day, and it’s why security teams, CISA, and threat intelligence firms all flagged it the same week. A patch sitting unapplied on a laptop or server is a known door left open, and attackers who specialize in espionage campaigns, like the group tied to this one, tend to look for exactly that kind of opening rather than trying something noisier.
Which systems are exposed?
The vulnerability affects Windows 10 (multiple supported builds), Windows 11 versions 24H2 and 26H1, and Windows Server releases from 2012 through 2025, including Server Core installs. In practice, that covers almost any Windows machine still receiving updates, from a receptionist’s desktop to a domain controller in a server closet. If your business has any device that hasn’t pulled updates automatically, from a remote worker’s laptop to an old file server kept around for one legacy app, assume it needs the August cumulative update.
What should a Boston small business do this week?
Start by confirming the August cumulative updates actually installed, not just that Windows Update ran. If you manage devices through Intune, WSUS, or a remote monitoring tool, pull a compliance report and chase down anything still pending. Reboot machines that show updates as “pending restart,” since an unrestarted device is still vulnerable even after downloading the fix. If you have any Windows Server 2016 or 2012 R2 boxes in the mix, treat this patch as a forcing function to also plan their retirement, since both are approaching or past end of support. Finally, make sure endpoint detection is actually running and reporting, because a patch closes the door attackers used to get in this time, not the one they’ll try next.
How does this fit the monthly patching routine?
Patch Tuesday lands the second Tuesday of every month, and we’ve covered the July 2026 release here as well. The pattern holds: most months bring routine fixes, and a handful of months bring something like this, a flaw already being exploited when the fix arrives. A monthly patching habit, rather than a “get to it eventually” approach, is what keeps a business from being the one still exposed weeks after a fix exists.
Frequently asked questions
Do I need to do anything beyond running Windows Update?
For most small offices, installing the August cumulative update through Windows Update, Intune, or WSUS is enough. The gap usually isn’t the patch itself, it’s devices that silently failed to update or never rebooted to finish installing it.
Is my business a target just because a nation-state group is involved?
Not directly. Groups like Lazarus typically chase specific targets for espionage or theft, but the tools and exploits they use often get reused by less sophisticated criminals within weeks. Patching removes the vulnerability regardless of who eventually tries to use it.
What if I still have a Windows Server 2016 machine I can’t take offline yet?
Apply the August security update to it immediately, since it’s on the affected list, and start planning its replacement now given the January 2027 end-of-support date. A server past end of support stops receiving fixes like this one entirely.
How do I know if this patch actually installed on all our devices?
Check your patch management or RMM dashboard for the August 2026 cumulative update KB number tied to each Windows version, and look specifically for devices stuck in a “pending reboot” or “failed” state rather than just trusting a completed percentage.
An actively exploited kernel flaw with nation-state fingerprints on it isn’t a normal Tuesday, and confirming every device in your office is actually patched, not just scheduled to be, is worth thirty minutes this week. If you want a second set of eyes on your patch compliance or a broader look at how your Microsoft 365 environment is configured, Boston Managed IT offers a free 15-minute Microsoft 365 or security review. Call (617) 322-5155 or visit bostonmit.com/contact to set one up.
— Boston Managed IT