Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft’s latest Patch Tuesday fixes an actively exploited Windows kernel driver flaw, CVE-2026-68820, which can let an attacker escalate to SYSTEM. It also closes four unauthenticated 9.8-rated remote code execution bugs in Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack, plus the remaining half of a SharePoint attack chain. #CVE-2026-68820 #afd.sys #WindowsDNSServer #WindowsDeploymentServices #MicrosoftQUIC #HPCPack #SharePoint #CVE-2026-55040 #CVE-2026-63520

Keypoints

  • CVE-2026-68820 is being actively exploited and affects the Windows kernel driver afd.sys.
  • The flaw is a use-after-free bug that can escalate an attacker to SYSTEM.
  • Four unauthenticated RCE vulnerabilities score 9.8 and affect DNS Server, WDS, QUIC, and HPC Pack.
  • Microsoft also released the final fix for a SharePoint exploit chain completed with CVE-2026-63520.
  • Patch priority should be based on exploit status, service exposure, and whether affected components are installed.

Read More: https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html