Microsoft Addresses 398 Vulnerabilities, Including Actively Exploited Zero-Day

Microsoft has released its latest Patch Tuesday updates, addressing a total of 398 security vulnerabilities across its software portfolio. Among these, a critical zero-day flaw in the Windows Ancillary Function Driver (afd.sys) has been identified as actively exploited in the wild.

Zero-Day Vulnerability in Windows Kernel Driver

The actively exploited vulnerability, designated as CVE-2026-68820 with a CVSS score of 7.0, resides in the Windows kernel’s afd.sys driver, which manages network socket operations. This flaw allows attackers with existing access to a system to escalate their privileges to the SYSTEM level by exploiting a race condition within the driver. Security researchers have linked this vulnerability to the Lazarus Group’s Operation Dream Job campaign.

Critical Remote Code Execution Flaws

In addition to the zero-day, Microsoft has patched four critical remote code execution (RCE) vulnerabilities, each carrying a CVSS score of 9.8. These flaws are particularly concerning as they can be exploited remotely without requiring authentication or user interaction:

  • CVE-2026-62878: A stack-based buffer overflow in Windows DNS Server, potentially wormable, though Microsoft rates exploitation as less likely.
  • CVE-2026-62893: A vulnerability in Windows Deployment Services’ TFTP handling, allowing remote code execution without authentication.
  • CVE-2026-62815: An issue in Microsoft’s implementation of the QUIC transport protocol, enabling unauthenticated remote code execution.
  • CVE-2026-59124: A flaw in High Performance Computing (HPC) Pack, rated as Important due to its non-default installation status, but still carrying a high severity score.

Completion of SharePoint Security Fixes

This month’s updates also finalize a two-part remediation for a SharePoint vulnerability chain. In July, Microsoft addressed CVE-2026-55040, an authentication bypass flaw. The August update now fixes the associated remote code execution vulnerability, completing the patching process for this exploit chain. Organizations using on-premises SharePoint servers are advised to apply both updates promptly to mitigate potential risks.

Given the severity and nature of these vulnerabilities, it is imperative for organizations to prioritize the deployment of these patches. The actively exploited zero-day in the Windows kernel driver, along with the critical RCE flaws, pose significant security risks. Timely updates are essential to protect systems from potential attacks.