A Windows Bug Under Active Attack Needs More Than a Patch — It Needs a Reboot
CISA added a Windows kernel driver flaw to its exploited-vulnerabilities catalog this month after hackers used it to plant a rootkit. Installing the update alone does not fix it — the repair only takes effect after a restart.
Meridians Money Desk
Published 26 August 2026 · Updated 26 August 2026 · 4 min read
SoftwareThe short answer
- Microsoft's August 2026 Patch Tuesday fixed 400 vulnerabilities on August 11, including 42 rated critical and three zero-days.
- CISA added CVE-2026-68820, a Windows WinSock driver flaw exploited by the Lazarus group to deploy the FudModule rootkit, to its Known Exploited Vulnerabilities catalog on August 11.
- Because the fix replaces a kernel driver, CISA's guidance says installing the patch alone does not complete remediation — the system must also be rebooted.
- Under CISA directive BOD 26-04, federal agencies had 3 days to fix internet-facing systems and 14 days for internal systems — the internal deadline fell on August 25.
Microsoft's August 2026 Patch Tuesday, released August 11, fixed 400 vulnerabilities across its products, including 42 rated critical. Three of those were zero-days — flaws already known before a fix existed. One of them is now confirmed under active attack, and the U.S. Cybersecurity and Infrastructure Security Agency says patching it is only half the job.
The flaw that's under active attack
CVE-2026-68820 is an elevation-of-privilege bug in the Windows Ancillary Function Driver for WinSock (afd.sys), a core networking component. CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on August 11, the same day Microsoft shipped the fix. Security researchers tracking the exploitation attribute it to Lazarus, a North Korea-linked hacking group, which used the flaw to deploy a rootkit called FudModule — malware designed to hide deep in the operating system and survive normal cleanup.
Two more zero-days, not yet reported exploited
- CVE-2026-62832 — a Windows User Profile Service elevation-of-privilege flaw, sometimes referred to as "LegacyHive," publicly disclosed before Microsoft's fix shipped.
- CVE-2026-72971 — a tampering vulnerability in the Windows Container Isolation FS Filter Driver, also publicly disclosed ahead of the patch.
Why a patch alone doesn't finish the job
CISA's guidance on CVE-2026-68820 notes that because the fix replaces a kernel-level driver, installing the update does not fully remediate the system until it has been rebooted. Under CISA's Binding Operational Directive 26-04, which sets risk-based remediation windows of 3 to 14 days depending on exposure, federal civilian agencies had until August 14 to fix internet-facing systems and until August 25 — yesterday — to fix internal, non-exposed ones.
If you haven't restarted a Windows machine since early August, checking for updates isn't enough on its own. Go to Settings > Windows Update, confirm the August cumulative update is installed, and reboot — the driver replacement doesn't take effect until the system restarts.
Sources
Every factual claim above is traceable to these documents. Check them — that is why they are here.
About this byline
Meridians Money Desk is an editorial desk at Meridians, not an individual. A desk byline means the article was produced and fact-checked to that desk's published standards. Read our editorial standards and corrections policy.
Sponsored
Paid placement · not editorial
Apple Fixes Nearly 30 Security Flaws in iOS, iPadOS and macOS — Here's Why to Update Now
4 min read · 21 August 2026
CISA Sets a Same-Week Deadline for Four Actively Exploited Bugs. One Scores a Perfect 10.
4 min read · 13 September 2026
Microsoft's September Patch Fixes Two Windows Flaws Already Under Attack
4 min read · 9 September 2026
The Meridians Brief
One considered email a week
What changed, what it costs you, and what to do about it — from the Meridians desks. No sponsored picks disguised as recommendations.
Sign-up opens with our launch issue. Nothing is sent or stored yet.
