Microsoft Patched 400-Plus Flaws This Month — One Was Already Being Used to Plant a Rootkit
A Windows driver bug linked to North Korea's Lazarus Group was under active attack before the fix shipped. Researchers say installing August's update isn't optional.
Meridians Money Desk
Published 21 August 2026 · Updated 21 August 2026 · 4 min read
SoftwareThe short answer
- Microsoft's August 2026 Patch Tuesday fixed several hundred CVEs across Windows, Office, SharePoint, Azure and Exchange, with dozens rated Critical.
- One zero-day, CVE-2026-68820 in the Windows Ancillary Function Driver (afd.sys), was being actively exploited. Researcher Satnam Narang linked it to the pattern behind three prior afd.sys zero-days since 2022.
- Check Point researchers say the Lazarus Group used the flaw to deploy a new version of its FudModule kernel-mode rootkit after gaining SYSTEM-level privileges.
- Windows users get the fix through the standard cumulative updates, including KB5121003, KB5120240 and KB5120249; Microsoft and independent researchers both recommend installing them without delay.
Microsoft's August 2026 security update round included a fix for a Windows flaw that attackers were already using in the wild — reportedly to install a rootkit tied to North Korea's Lazarus Group.
What's being exploited right now
CVE-2026-68820 is a use-after-free bug in afd.sys, the kernel-mode driver behind Windows networking (WinSock). A locally authenticated attacker can trigger a race condition to gain SYSTEM-level privileges — the highest level of access on a Windows machine. Check Point researchers say Lazarus used it to deploy a new version of FudModule, the group's kernel-mode rootkit.
This is at least the fourth afd.sys zero-day exploited in the wild since 2022, following CVE-2025-32709, CVE-2025-21418 and CVE-2024-38193, according to security researcher Satnam Narang.
The rest of the month's patches
Counts vary slightly by source. BleepingComputer, citing Microsoft's release notes, counted 400 flaws fixed, including three zero-days and 42 Critical-rated vulnerabilities. SecurityWeek's tally put the total at 421 CVEs, broken down across Windows (236), Office (196), SharePoint Server (30), developer tools (26), Azure (17) and Exchange Server (7).
What to do
- Install this month's Windows cumulative update as soon as possible — KB5121003 and KB5120240 for Windows 11, KB5120249 for Windows 10
- Prioritize systems running Exchange Server and SharePoint Server, which carry several of the Critical-rated flaws
- Update Microsoft Office separately if it isn't set to auto-update
- Restart affected machines after installing — kernel-level fixes like this one require a reboot to take effect
Sources
Every factual claim above is traceable to these documents. Check them — that is why they are here.
About this byline
Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.
Sponsored
Paid placement · not editorial
CISA Sets a Same-Week Deadline for Four Actively Exploited Bugs. One Scores a Perfect 10.
4 min read · 13 September 2026
Microsoft's September Patch Fixes Two Windows Flaws Already Under Attack
4 min read · 9 September 2026
Google Confirms Active Attacks Exploiting a Chrome Flaw. Patch Now, Then Check Every Chromium Browser You Use
3 min read · 6 September 2026
The Meridians Brief
One considered email a week
What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.
Sign-up opens with our launch issue. Nothing is sent or stored yet.