Skip to content
LIVE

Microsoft Patched 400-Plus Flaws This Month — One Was Already Being Used to Plant a Rootkit

A Windows driver bug linked to North Korea's Lazarus Group was under active attack before the fix shipped. Researchers say installing August's update isn't optional.

Meridians Money Desk

Published 21 August 2026 · Updated 21 August 2026 · 4 min read

Microsoft Patched 400-Plus Flaws This Month — One Was Already Being Used to Plant a RootkitSoftware
Photo: Photo by cottonbro studio / Pexels (Pexels License — free to use, no attribution legally required (credited above as good practice).)

The short answer

  • Microsoft's August 2026 Patch Tuesday fixed several hundred CVEs across Windows, Office, SharePoint, Azure and Exchange, with dozens rated Critical.
  • One zero-day, CVE-2026-68820 in the Windows Ancillary Function Driver (afd.sys), was being actively exploited. Researcher Satnam Narang linked it to the pattern behind three prior afd.sys zero-days since 2022.
  • Check Point researchers say the Lazarus Group used the flaw to deploy a new version of its FudModule kernel-mode rootkit after gaining SYSTEM-level privileges.
  • Windows users get the fix through the standard cumulative updates, including KB5121003, KB5120240 and KB5120249; Microsoft and independent researchers both recommend installing them without delay.

Microsoft's August 2026 security update round included a fix for a Windows flaw that attackers were already using in the wild — reportedly to install a rootkit tied to North Korea's Lazarus Group.

What's being exploited right now

CVE-2026-68820 is a use-after-free bug in afd.sys, the kernel-mode driver behind Windows networking (WinSock). A locally authenticated attacker can trigger a race condition to gain SYSTEM-level privileges — the highest level of access on a Windows machine. Check Point researchers say Lazarus used it to deploy a new version of FudModule, the group's kernel-mode rootkit.

This is at least the fourth afd.sys zero-day exploited in the wild since 2022, following CVE-2025-32709, CVE-2025-21418 and CVE-2024-38193, according to security researcher Satnam Narang.

The rest of the month's patches

Counts vary slightly by source. BleepingComputer, citing Microsoft's release notes, counted 400 flaws fixed, including three zero-days and 42 Critical-rated vulnerabilities. SecurityWeek's tally put the total at 421 CVEs, broken down across Windows (236), Office (196), SharePoint Server (30), developer tools (26), Azure (17) and Exchange Server (7).

What to do

  1. Install this month's Windows cumulative update as soon as possible — KB5121003 and KB5120240 for Windows 11, KB5120249 for Windows 10
  2. Prioritize systems running Exchange Server and SharePoint Server, which carry several of the Critical-rated flaws
  3. Update Microsoft Office separately if it isn't set to auto-update
  4. Restart affected machines after installing — kernel-level fixes like this one require a reboot to take effect

Sources

Every factual claim above is traceable to these documents. Check them — that is why they are here.

About this byline

Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.

Sponsored

Paid placement · not editorial

Related reading

The Meridians Brief

One considered email a week

What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.

Sign-up opens with our launch issue. Nothing is sent or stored yet.