Zero Day Room
Live
Regulation & compliance

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack.

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

## Windows Driver Zero-Day Under Active Attack Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack. The bug, tracked as CVE-2026-68820, is a use-after-free in the Ancillary Function Driver for WinSock (afd.sys) and is the only flaw in this month's release flagged as under active exploitation by Microsoft. According to Check Point Research, the zero-day was used in the Operation Dream Job campaign by the Lazarus group. The flaw is a privilege escalation, allowing an attacker with code already running on a machine to use it to reach SYSTEM. Microsoft has not publicly attributed the exploitation of this flaw. ## Four Unauthenticated Remote Code Execution Flaws In addition to the Windows driver zero-day, four other flaws in the release require no account, no password, and no click to exploit. These flaws affect Windows DNS Server, Windows Deployment Services, Microsoft's implementation of the QUIC transport protocol, and High Performance Computing (HPC) Pack. Each of these flaws carries a CVSS score of 9.8 and is considered a Critical vulnerability. - CVE-2026-62878 is a stack-based buffer overflow in Windows DNS Server that is reachable remotely with no authentication and no user interaction. - CVE-2026-62893 is a remote flaw in Windows Deployment Services that is reachable through the service's TFTP handling without authentication or user interaction. - CVE-2026-62815 is a remote, unauthenticated code execution flaw in Microsoft QUIC that requires no user interaction. - CVE-2026-59124 is a remote, unauthenticated code execution flaw in HPC Pack that is rated Important rather than Critical because HPC Pack is not installed by default. ## A SharePoint Chain Closes The release also completes a two-part SharePoint fix that started in July. The July update fixed the first half of the fix, CVE-2026-55040, a Critical authentication bypass scored at 9.1. The August update supplies the fix for the RCE component, identified as CVE-2026-63520. The distinction matters, as CVE-2026-63520 is the code execution half of the chain, not by itself the unauthenticated condition. Rapid7 Labs reported an exploit chain to Microsoft on May 18 that combined an authentication bypass with a separate code execution vulnerability to reach unauthenticated RCE against on-premises SharePoint. Microsoft confirmed two days later that it planned to split the remediation across the July and August update cycles. The Zero Day Initiative puts the release at 398 new CVEs, 62 of them rated Critical. The count shows the size of the release; exploit status and reach decide the patch order.

Related coverage

More from Regulation & compliance