Microsoft August Patch Fixes Windows Privilege Escalation Flaw Exploited by Lazarus
Microsoft released its regular security update on August 11, 2026 (local time). This update resolves a total of 398 to 421 flaws.
The highlight of this patch is a Windows kernel zero-day vulnerability (CVE-2026-68820) exploited in real-world attacks by the North Korean-linked hacking group Lazarus. Stemming from a use-after-free flaw in the Windows Ancillary Function Driver (AFD.sys), Lazarus exploited this as a zero-day to steal system-level privileges. Microsoft released details on the vulnerability and countermeasures, noting that attackers could trigger a race condition to attempt privilege escalation.
This update includes four critical flaws (such as CVE-2026-62878) that allow for remote code execution without user authentication or interaction. Additionally, it fixes additional flaws that threatened SharePoint in conjunction with an authentication bypass vulnerability discovered last July.
