August Patch Tuesday: Windows Zero-Day Under Active Attack
On 11 August 2026, Microsoft released its monthly security update. Patch Tuesday – the second Tuesday of every month, when Microsoft issues security fixes for Windows, Office and related products – is a fixture in the IT calendar, but this month’s release stands out. It covers around 400 separate vulnerabilities across Windows, Microsoft 365, Azure and other products, and one of those is already being actively exploited by a sophisticated, state-sponsored hacking group.
Here is what it means for your business and what needs to happen now.
The urgent one: CVE-2026-68820
The vulnerability demanding the most immediate attention is CVE-2026-68820, a flaw in the Windows Ancillary Function Driver for WinSock. WinSock (Windows Sockets) is the low-level Windows component that handles all network communication. The driver involved, afd.sys, runs in the Windows kernel – the most privileged layer of the operating system, where the rules of user space do not apply.
The flaw is a use-after-free bug: a type of memory error that allows software to behave in unintended ways by referencing memory that has already been freed. In this case, an attacker who is already authenticated on a Windows machine can exploit a race condition to elevate their privileges to SYSTEM level – the highest level of access available on a Windows computer – without any additional user interaction.
Microsoft has confirmed this vulnerability is being actively exploited in the wild. Security researchers have attributed the exploitation to Lazarus Group, the North Korean state-sponsored hacking organisation, which is reported to have used the flaw to deploy an updated version of FudModule – a kernel-level rootkit designed to conceal malware deep within Windows, well below where most security tools operate.
A kernel rootkit is worth explaining. Most malicious software runs in user space – the layer where applications run – where security tools can detect and remove it. A rootkit embedded in the kernel can conceal other malicious processes, disable security software and survive reboots. It represents a significant escalation in attack sophistication.
Why this matters for your business
Your business is almost certainly not a direct target for North Korean state hackers. But that is not the only risk here.
Exploit code for confirmed zero-days – vulnerabilities already being actively used against real targets – circulates rapidly in criminal circles. Within days or weeks of a public disclosure, the same technique frequently appears in ransomware toolkits and automated attack tools aimed at businesses of all sizes and sectors.
The reason this particular flaw matters for ransomware specifically is the type of vulnerability it is. Most successful ransomware attacks follow two stages: first, a foothold is gained (typically via phishing, a stolen credential, or an exposed service); second, the attacker escalates their privileges so they can move freely across the network, disable backups and deploy ransomware widely. CVE-2026-68820 is exactly the kind of flaw used in that second step. Patching it removes that escalation path.
Other notable patches this month
Alongside the actively exploited zero-day, this month’s update includes two further vulnerabilities that have been publicly disclosed – meaning details are already in the open, and the window before exploitation widens is short:
- CVE-2026-64898 – Microsoft Office Remote Code Execution (Critical). An attacker can craft a malicious Office file; opening it triggers code execution on the target machine. Given how routinely Office documents are shared with clients and suppliers, this should be treated as urgent even though active exploitation has not yet been confirmed.
- CVE-2026-71331 – Microsoft Azure Attestation Service RCE (Critical). Relevant to organisations using cloud-based device health verification as part of their security or compliance setup.
Windows Deployment Services also received a patch for a network-exploitable remote code execution vulnerability (CVE-2026-62893) affecting Windows Server environments.
What we have already done for managed clients
For businesses on our managed IT support plan, we deploy Windows security updates and patch third-party software across all managed endpoints through our remote management platform. The critical patches from this Patch Tuesday – including CVE-2026-68820 – are being pushed this week as a priority deployment.
If you have specific questions about patch status on your devices, or would like confirmation that your environment is fully covered, please contact us and we will check for you.
What to do if you manage IT in-house
If you handle your own IT, the immediate steps are straightforward:
- Run Windows Update on all devices and confirm the August cumulative update has installed. Windows 11 users should be on build KB5121003 (version 26100.9168 for Windows 11 24H2, or 26200.9168 for 25H2).
- Ensure Microsoft 365 and Office are fully updated. In the Microsoft 365 Admin Centre, confirm that automatic update deployment is active and that recent updates have been applied.
- Check your endpoint security is current and actively scanning. Patching Windows closes the vulnerability, but your endpoint protection needs to be up to date too – particularly for threats that may have already gained a foothold before the patch lands.
If patch management is currently manual or irregular in your organisation, this month is a timely reminder of the risk that creates. Missed patches remain one of the most consistent root causes of successful ransomware attacks on UK businesses.
Our IT security services and IT support and maintenance plans include automated, monitored patch management across Windows, Microsoft 365 and third-party applications as standard, so nothing falls through the gaps between monthly updates.
If you would like a review of your current patch management process, or to discuss moving to a fully managed plan, get in touch or call 01452 701355 for a no-obligation conversation.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


