Skip to content
LIVE

A Windows Bug Under Active Attack Needs More Than a Patch — It Needs a Reboot

CISA added a Windows kernel driver flaw to its exploited-vulnerabilities catalog this month after hackers used it to plant a rootkit. Installing the update alone does not fix it — the repair only takes effect after a restart.

Meridians Money Desk

Published 26 August 2026 · Updated 26 August 2026 · 4 min read

A Windows Bug Under Active Attack Needs More Than a Patch — It Needs a RebootSoftware
Photo: Photo by cottonbro studio / Pexels (Pexels License — free to use, no attribution legally required (credited above as good practice).)

The short answer

  • Microsoft's August 2026 Patch Tuesday fixed 400 vulnerabilities on August 11, including 42 rated critical and three zero-days.
  • CISA added CVE-2026-68820, a Windows WinSock driver flaw exploited by the Lazarus group to deploy the FudModule rootkit, to its Known Exploited Vulnerabilities catalog on August 11.
  • Because the fix replaces a kernel driver, CISA's guidance says installing the patch alone does not complete remediation — the system must also be rebooted.
  • Under CISA directive BOD 26-04, federal agencies had 3 days to fix internet-facing systems and 14 days for internal systems — the internal deadline fell on August 25.

Microsoft's August 2026 Patch Tuesday, released August 11, fixed 400 vulnerabilities across its products, including 42 rated critical. Three of those were zero-days — flaws already known before a fix existed. One of them is now confirmed under active attack, and the U.S. Cybersecurity and Infrastructure Security Agency says patching it is only half the job.

The flaw that's under active attack

CVE-2026-68820 is an elevation-of-privilege bug in the Windows Ancillary Function Driver for WinSock (afd.sys), a core networking component. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on August 11, the same day Microsoft shipped the fix. Security researchers tracking the exploitation attribute it to Lazarus, a North Korea-linked hacking group, which used the flaw to deploy a rootkit called FudModule — malware designed to hide deep in the operating system and survive normal cleanup.

Two more zero-days, not yet reported exploited

  • CVE-2026-62832 — a Windows User Profile Service elevation-of-privilege flaw, sometimes referred to as "LegacyHive," publicly disclosed before Microsoft's fix shipped.
  • CVE-2026-72971 — a tampering vulnerability in the Windows Container Isolation FS Filter Driver, also publicly disclosed ahead of the patch.

Why a patch alone doesn't finish the job

CISA's guidance on CVE-2026-68820 notes that because the fix replaces a kernel-level driver, installing the update does not fully remediate the system until it has been rebooted. Under CISA's Binding Operational Directive 26-04, which sets risk-based remediation windows of 3 to 14 days depending on exposure, federal civilian agencies had until August 14 to fix internet-facing systems and until August 25 — yesterday — to fix internal, non-exposed ones.

If you haven't restarted a Windows machine since early August, checking for updates isn't enough on its own. Go to Settings > Windows Update, confirm the August cumulative update is installed, and reboot — the driver replacement doesn't take effect until the system restarts.

Sources

Every factual claim above is traceable to these documents. Check them — that is why they are here.

About this byline

Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.

Sponsored

Paid placement · not editorial

Related reading

The Meridians Brief

One considered email a week

What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.

Sign-up opens with our launch issue. Nothing is sent or stored yet.