Microsoft Patches 398 Flaws Including Zero-Day Used by Lazarus Group

by priyanka.patel tech editor
Microsoft Patches 398 Flaws Including Zero-Day Used by Lazarus Group

Microsoft released a security update on August 11, 2026, patching 398 vulnerabilities. The rollout includes a Windows driver zero-day already exploited in the wild by North Korea’s Lazarus group, alongside four unauthenticated remote code execution flaws carrying severity scores of 9.8.

The Active Zero-Day in afd.sys and the Lazarus Group Campaign

Security researchers called the threat on Tuesday, noting that the tradecraft behind the driver flaw pointed to an APT group. Hours later, Check Point Research published an analysis identifying the operator as North Korea’s Lazarus group. The flaw, tracked as CVE-2026-68820 with a CVSS score of 7.0, resides in the Ancillary Function Driver for WinSock (afd.sys), a core kernel-side component handling Windows networking socket operations.

An attacker who already has code running locally on a target machine can exploit a race condition in the driver to escalate privileges directly to SYSTEM. Check Point reported the vulnerability to Microsoft on July 28, estimating the campaign began as early as June or early July. Targets included defense, aerospace, and aviation firms across France, Germany, Brazil, and India.

The delivery mechanism leveraged fake job offers distributed likely through LinkedIn, leading targets to trojanized builds or signed PDF viewers with malicious DLL side-loading. The resulting payload deployed an updated build of FudModule, a kernel-mode rootkit capable of tampering with Windows software trust verification.

Four Maximum-Severity Server Flaws Waiting in the Wings

While the driver zero-day demands immediate triage due to active exploitation, security analysts emphasize four remote code execution vulnerabilities that carry a base CVSS score of 9.8. Each of these requires no user interaction, no password, and no account credentials from a victim.

  • CVE-2026-62878: A stack-based buffer overflow in Windows DNS Server, described by the Zero Day Initiative as technically wormable.
  • CVE-2026-62893: A remote vulnerability in Windows Deployment Services accessible via TFTP handling.
  • CVE-2026-62815: An unauthenticated code execution flaw within the Microsoft QUIC transport protocol implementation.
  • CVE-2026-59124: A flaw in HPC Pack, rated Important rather than Critical because the package is not installed by default.

Industry specialists warn that service inventory dictates priority for these server-side holes. The only bug in this release Microsoft confirms is being exploited in the wild, and that outranks every bigger number on the advisory sheet, noted Jason Kikta, Automox CTO regarding the triage decision.

Completing the On-Premises SharePoint Chain

The August rollout also finalizes a two-part remediation addressing an unauthenticated remote code execution chain against on-premises SharePoint farms. Rapid7 Labs originally reported the exploit chain on May 18. The attack sequence combined an authentication bypass with a separate code execution vulnerability.

Microsoft Patches 398 Flaws Including Zero-Day Used by Lazarus Group
Photo: csoonline.com

Microsoft split the fix across the July and August update cycles. The July update deployed CVE-2026-55040, a 9.1-rated authentication bypass allowing attackers to impersonate site users or administrators. The August release supplies the fix for the RCE component, identified as CVE-2026-63520. Organizations that applied the July patch already broke the demonstrated exploit chain, but administrators must deploy the August update to fully close the vulnerability.

Counting the CVEs: Why Publications Disagree

Security outlets reported varying counts for the August Patch Tuesday release, reflecting differences in tracking methodology rather than discrepancies in Microsoft’s underlying package. Tenable tallied 398 CVEs, omitting two MITRE-assigned entries. BleepingComputer counted 400, SecurityWeek and The Register reported 421, and CyberSecurityNews recorded 394.

Microsoft Patches 398 Flaws Including Zero-Day Used by Lazarus Group
Photo: itwire.com

Regardless of the exact total, security leaders note that massive update volumes have become standard operating procedure. While this month’s release is smaller than last month’s, 398 new CVEs prove that massive patch loads are officially the ‘new normal,’ said Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative.

Remediation Deadlines and Next Steps

The Cybersecurity and Infrastructure Security Agency added CVE-2026-68820 to its Known Exploited Vulnerabilities catalogue on Tuesday, establishing a mandatory U.S. federal remediation deadline of August 25, 2026. Security teams face pressure to patch the winSock driver flaw immediately, followed by publicly disclosed elevation-of-privilege flaws such as CVE-2026-62832 in the Windows User Profile Service.

SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Moz…

You may also like