Threat reportVulnerabilityTL-2026-1987
Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)
Microsoft August 2026 Patch Tuesday (TL-2026-1987), also tracked as LegacyHive, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-08-11 and last reviewed 2026-10-08. It is attributed to Lazarus Group (North Korea) with high confidence, affects Microsoft Windows Ancillary Function Driver for WinSock (AFD.sys), references 54 CVEs (CVE-2026-68820, CVE-2026-62832, CVE-2026-72971), maps to 64 MITRE ATT&CK techniques (T1005, T1012, T1014), and is covered by 9 detection rules and 72 indicators of compromise.
- CVSS
- 9.9/10Critical
- CVEs
- 54Referenced vulnerabilities
- Techniques
- 64MITRE ATT&CK
- Actors
- 1Lazarus Group
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 72Indicators of compromise
Key facts for TL-2026-1987
- Threat ID
- TL-2026-1987
- Also known as
- LegacyHive
- Severity
- CRITICAL
- CVSS
- 9.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- Lazarus Group
- Attribution confidence
- HIGH
- Nation-state nexus
- North Korea
- Motivation
- ESPIONAGE
- Target sectors
- financial services, banking, defense, aerospace, technology, critical infrastructure electric grid, entertainment
- Target regions
- Global, united states of america, Europe, Latin America
- Detection rules
- 9
- Indicators of compromise
- 72
- Updates
- 2026-10-08 · 10 updates · revalidated 10× · latest source
Malware and tooling in Microsoft August 2026 Patch Tuesday
Malware and tooling: FudModule, CVE-2026-68820 AFD.sys use-after-free exploit, LegacyHive PoC exploit
How Microsoft August 2026 Patch Tuesday works
Microsoft's August 2026 Patch Tuesday fixed 400 vulnerabilities, including three zero-days: CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock (AFD.sys) actively exploited by the North Korean Lazarus Group to deploy its FudModule kernel-mode rootkit, and two publicly disclosed zero-days — CVE-2026-62832 ("LegacyHive", a Windows User Profile Service link-following flaw whose PoC was released a month earlier) and CVE-2026-72971 (Windows Container Isolation FS Filter Driver / unionfs.sys tampering). The release also addressed 42 Critical vulnerabilities (37 RCE, 5 EoP) across Windows and Azure components.
On August 11, 2026, Microsoft released its August Patch Tuesday update, resolving 400 vulnerabilities across its product line — a decrease from July 2026's record 570 but still far above historical norms, which Microsoft attributed in part to an internal AI-powered vulnerability discovery system surfacing additional flaws.
The headline item is CVE-2026-68820, a use-after-free (CWE-416) in AFD.sys, the Ancillary Function Driver for WinSock that is installed by default on every Windows system and provides kernel-mode support for the Winsock networking stack. The flaw lets an authorized local attacker win a race condition to escalate to SYSTEM privileges (CVSS 3.1 7.0, AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Check Point Research, publishing findings concurrently with the patch, attributed active in-the-wild exploitation of this flaw to the North Korean Lazarus Group, which used it to deploy FudModule, its purpose-built kernel-mode rootkit. Because AFD.sys ships by default, this exploitation required no separate Bring-Your-Own-Vulnerable-Driver (BYOVD) staging step of the kind Lazarus has previously used with third-party drivers. Microsoft credits Check Point researchers Moshe Marelus and David Driker with the discovery.
FudModule's broader tradecraft — documented across its evolving versions by researchers including Gen Digital — corrupts the exploited thread's PreviousMode field to gain a kernel read/write primitive (routed exclusively through NtWriteVirtualMemory to minimize telemetry), then uses that primitive to strip registry, object, process/thread/image-load, and image-verification kernel callbacks; unlink AV/EDR minifilter drivers; suppress Windows Filtering Platform callouts; zero ETW's active system logger list and disable roughly 95 ETW provider GUIDs; strip Protected Process Light (PPL) protection from security products (e.g., AhnLab's asdsvc.exe); and suspend threads inside Microsoft Defender, CrowdStrike Falcon, and HitmanPro via direct handle-table manipulation. The rootkit records which techniques executed successfully to a marker file historically named tem1245.tmp.
CVE-2026-62832 is an improper link-resolution flaw (CWE-59, CVSS 3.1 7.8) in the Windows User Profile Service (ProfSvc) that lets a low-privileged, authenticated attacker force the SYSTEM-level service to load another user's — potentially an administrator's — registry hive under the attacker's own profile, exposing that data or enabling further privilege escalation. This is the vulnerability behind "LegacyHive," a PoC independent researcher Nightmare Eclipse (MSNightmare) publicly released on July 15, 2026, roughly a month before Microsoft's fix. The exploit chains registry poisoning, object-manager symbolic links, and a TOCTOU race won via an opportunistic lock (oplock) on a decoy file to swap a symlink at the exact moment ProfSvc loads the target hive; it reportedly worked against fully patched Windows 10, Windows 11, and Windows Server (2016/2019/2022) systems with no interim Microsoft mitigation available prior to this release.
CVE-2026-72971 is a related-class improper link-resolution flaw (CWE-59, CVSS 3.1 5.5, high integrity impact) in unionfs.sys, the Windows Container Isolation FS Filter Driver that enforces isolation for Windows containers, affecting Windows 11 26H1 (x64/ARM64) builds prior to 10.0.28000.2704. Microsoft credits researchers identified as yhw and txz.
Beyond the three zero-days, the release fixed 42 Critical vulnerabilities (37 RCE, 5 EoP), including RCEs in Active Directory Certificate Services, Azure Confidential Ledger, Azure Service Bus, Windows DHCP Server, Windows DNS Server (four separate CVEs), Microsoft QUIC, Windows RRAS, Windows SSTP, Windows Deployment Services TFTP, and the Remote Desktop Client, plus Critical EoP/spoofing issues in Application Insights Profiler, Azure Active Directory, Azure Entra ID, Microsoft Exchange Server, and Microsoft Entra Provisioning Service.
MITRE ATT&CK techniques used in TL-2026-1987
Collection
T1005 Data from Local System; T1074.001 Data Staged; T1113 Screen Capture; T1560 Archive Collected Data; T1560.002 Archive Collected Data: Archive via Library
Discovery
T1012 Query Registry; T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.001 Account Discovery
Defense Evasion
T1014 Rootkit; T1027 Obfuscated Files or Information; T1036.005 Masquerading; T1036.008 Masquerading: Masquerade File Type; T1055 Process Injection; T1055.001 Process Injection; T1070.001 Indicator Removal: Clear Windows Event Logs; T1078.001 Valid Accounts: Default Accounts; T1140 Deobfuscate/Decode Files or Information; T1218.001 Signed Binary Proxy Execution: Msiexec; T1553.002 Subvert Trust Controls; T1553.006 Subvert Trust Controls: Code Signing Policy Modification; T1562.001 Impair Defenses; T1562.002 Impair Defenses; T1562.006 Impair Defenses; T1574.002 Hijack Execution Flow; T1620 Reflective Code Loading
Exfiltration
T1041 Exfiltration Over C2 Channel; T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration Over Web Service
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204.002 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1543.003 Create or Modify System Process: Windows Service; T1611 Escape to Host
Command and Control
T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1090 Proxy; T1090.003 Proxy: Multi-hop Proxy; T1102.002 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel; T1573.001 Encrypted Channel: Symmetric Cryptography
Initial Access
T1078 Valid Accounts; T1078.003 Valid Accounts; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.001 Phishing; T1566.002 Phishing
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Persistence
T1505.003 Server Software Component; T1547 Boot or Logon Autostart Execution; T1547.001 Boot or Logon Autostart Execution
Credential Access
T1550 Use Alternate Authentication Material; T1552.001 Unsecured Credentials; T1552.002 Unsecured Credentials
Impact
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1584.004 Compromise Infrastructure
Affected products and versions in Microsoft August 2026 Patch Tuesday
- Microsoft — Windows Ancillary Function Driver for WinSock (AFD.sys)
Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 23H2/24H2/25H2/26H1; Windows Server 2012-2025 (all 32-bit, x64, ARM64 builds)
Fixed in: Microsoft August 2026 cumulative security update - Microsoft — Windows User Profile Service (ProfSvc)
Vulnerable versions: Windows 10 21H2/22H2; Windows 11 23H2/24H2/25H2/26H1; Windows Server 2022/2025
Fixed in: Microsoft August 2026 cumulative security update - Microsoft — Windows Container Isolation FS Filter Driver (unionfs.sys)
Vulnerable versions: Windows 11 26H1 (x64, ARM64) prior to build 10.0.28000.2704
Fixed in: Windows 11 26H1 build 10.0.28000.2704 and later
Remediation for Microsoft August 2026 Patch Tuesday
Patches
- Microsoft August 2026 Patch Tuesday cumulative update resolving CVE-2026-68820 (AFD.sys use-after-free EoP)
- Microsoft August 2026 cumulative update resolving CVE-2026-62832 (Windows User Profile Service link-following EoP / LegacyHive)
- Microsoft August 2026 cumulative update resolving CVE-2026-72971 (unionfs.sys link-following tampering), Windows 11 26H1 build 10.0.28000.2704 and later
Immediate actions
- Apply Microsoft's August 2026 cumulative security updates addressing CVE-2026-68820, CVE-2026-62832, and CVE-2026-72971 immediately, prioritizing any system where AFD.sys exploitation may already be underway.
- Hunt for FudModule rootkit indicators: unexpected thread suspensions on MsMpEng.exe/CSFalconService.exe/HitmanPro processes, mass-disabled ETW providers, zeroed EtwpActiveSystemLoggers, and removed registry/object/process-thread-image kernel callbacks.
- Deploy and keep current Microsoft's Vulnerable Driver Blocklist and enable Hypervisor-protected Code Integrity (HVCI) where hardware supports it to raise the bar against kernel driver/UAF exploitation.
- Audit for anomalous Windows User Profile Service (ProfSvc) activity — unexpected registry hive loads under non-owning user profiles — as an interim detection for LegacyHive-class exploitation.
Workarounds
- No official Microsoft workaround was published for CVE-2026-62832 (LegacyHive) between its July 15, 2026 public PoC disclosure and the August 11, 2026 patch; the interim mitigation was monitoring for anomalous ProfSvc hive-load events.
- Restrict standard-user code execution on systems handling sensitive administrator sessions to reduce exposure to the local, authenticated-user exploitation vector shared by CVE-2026-68820, CVE-2026-62832, and CVE-2026-72971.
Longer-term hardening
- Adopt kernel-resilient EDR telemetry (e.g., independent hypervisor-based sensors) that survives callback-removal and handle-table-manipulation style evasion used by FudModule.
- Track public PoC disclosures for unpatched Windows internals bugs (LegacyHive-class link-following/TOCTOU races) and apply interim monitoring pending official patches, since standard privilege boundaries do not mitigate them.
- Restrict local logon and application-execution rights on high-value endpoints to reduce exposure to the shared local, low-privilege prerequisite (PR:L, local AV) across all three zero-days.
- Prioritize patching of the 42 Critical RCE/EoP flaws in this release on internet- and Azure-facing services (AD CS, DNS/DHCP/RRAS/SSTP, Azure Service Bus, Azure Confidential Ledger) given their network-reachable attack surface.
CVEs associated with Microsoft August 2026 Patch Tuesday
- CVE-2026-68820
- CVE-2026-62832
- CVE-2026-72971
- CVE-2026-62818
- CVE-2026-68823
- CVE-2026-50515
- CVE-2026-62823
- CVE-2026-62817
- CVE-2026-62820
- CVE-2026-65789
- CVE-2026-62878
- CVE-2026-62815
- CVE-2026-62819
- CVE-2026-62889
- CVE-2026-62893
- CVE-2026-62824
- CVE-2026-49163
- CVE-2026-50481
- CVE-2026-62869
- CVE-2026-62911
- CVE-2026-59115
- CVE-2026-65665
- CVE-2025-49113
- CVE-2026-62737
- CVE-2026-62816
- CVE-2026-68804
- CVE-2026-63526
- CVE-2026-68794
- CVE-2026-68816
- CVE-2026-63518
- CVE-2026-63525
- CVE-2026-64907
- CVE-2026-63515
- CVE-2026-70130
- CVE-2026-63532
- CVE-2026-64898
- CVE-2026-64903
- CVE-2026-64909
- CVE-2026-64910
- CVE-2026-64911
- CVE-2026-65657
- CVE-2026-62890
- CVE-2026-62822
- CVE-2026-64921
- CVE-2026-62827
- CVE-2026-70332
- CVE-2026-55040
- CVE-2026-63520
- CVE-2026-62910
- CVE-2026-62912
- CVE-2026-62913
- CVE-2026-62914
- CVE-2026-62915
- CVE-2026-65813
Weaknesses (CWE) in Microsoft August 2026 Patch Tuesday
CWE-416, CWE-59, CWE-502, CWE-122, CWE-822, CWE-121, CWE-471, CWE-415, CWE-294, CWE-918
Timeline of Microsoft August 2026 Patch Tuesday
Showing the 20 most recent tracked events.
- ACROS Security (0Patch), led by CEO Mitja Kolsek, releases a free unofficial micropatch for LegacyHive covering Windows 10 2004+ and Windows Server 2022+, redirecting the exploit to load a temporary profile hive instead of the targeted user's real hive.
- Check Point Research (Moshe Marelus, David Driker) reports the afd.sys use-after-free to Microsoft Security Response Center.
- Microsoft confirms the CVE-2026-68820 vulnerability report.
- Microsoft assigns CVE-2026-68820 to the confirmed afd.sys use-after-free.
- A Chinese-language proof-of-concept for CVE-2026-62737 (Windows Kernel untrusted pointer dereference, CVSS 7.8) is published.
- CVE-2026-62911 (Exchange Server capture-replay elevation of privilege) is publicly disclosed after a live Pwn2Own Berlin demonstration; ZDI advises treating exploitation as likely despite Microsoft's 'Less Likely' rating.
- Microsoft's advisory and Patch Tuesday press coverage clarify CVE-2026-62832 is 'publicly disclosed' with exploitation 'more likely,' distinct from CVE-2026-68820 (the afd.sys use-after-free), which is the single zero-day Microsoft confirms as actively exploited in the same batch; CVE-2026-62832 is absent from the CISA KEV catalog as of this release.
- Cisco Talos and Zero Day Initiative publish independent Patch Tuesday technical reviews covering the flagged CVEs and Snort/detection coverage.
- Check Point Research publishes 'Shattering the Dream,' detailing the CVE-2026-68820 exploit chain, FudModule v3.1, the SecurityPDF lure, and the Troy/MISTPEN/RelayShell tooling of a resurgent Operation Dream Job campaign.
- CISA adds CVE-2026-68820 to the Known Exploited Vulnerabilities catalog with a remediation due date of 2026-08-25.
- BleepingComputer publishes coverage summarizing the August 2026 Patch Tuesday release, the three zero-days, and Lazarus's exploitation of CVE-2026-68820.
- Check Point Research publishes findings, released concurrently with the patch, attributing in-the-wild exploitation of CVE-2026-68820 to the North Korean Lazarus Group, which used the flaw to deploy its FudModule kernel-mode rootkit.
- CVE-2026-72971 (Windows Container Isolation FS Filter Driver / unionfs.sys tampering) is published, credited to researchers identified as yhw and txz.
- CVE-2026-62832 (Windows User Profile Service link-following EoP, the LegacyHive flaw) is formally published, matching the July 2026 public PoC.
- CVE-2026-68820 (Windows AFD.sys use-after-free elevation of privilege) is published, credited to Check Point researchers Moshe Marelus and David Driker.
- Microsoft ships its August 2026 Patch Tuesday, fixing 400 vulnerabilities across its product line, including three zero-days and 42 Critical-rated flaws (37 RCE, 5 EoP).
- BleepingComputer and other outlets publish dedicated coverage of the Lazarus Group AFD.sys/FudModule campaign against defense firms, a day after the initial Patch-Tuesday-focused reporting.
- CISA adds CVE-2026-55040 (SharePoint JWT auth bypass) to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation following PoC publication.
- CISA BOD-mandated remediation deadline for CVE-2026-68820 per the KEV catalog entry.
- Upcoming end-of-life milestones tied to this release: Windows 11 24H2 Home & Pro end of servicing, Windows Server 2012/2012 R2 ESU expires, Office 2021/LTSC 2021 out of support, Exchange Server 2016/2019 enters permanent unsupported state.
Update history for TL-2026-1987
- 2026-10-08 — Microsoft August 2026 Patch Tuesday: afd.sys zero-day CVE-2026-68820 exploited by Lazarus (Operation Dream Job) to deploy FudModule 3.1 rootkit; LegacyHive CVE-2026-62832 patched: What changed No field escalation. Severity, exploitability, status, attribution and actor are unchanged. New indicators (2) 1 new Troy backdoor SHA-256 (a738059c...) and the MISTPEN screen-capture module OneScreenCapture64.dll. All other IO
- 2026-08-20 — Microsoft August 2026 Patch Tuesday — 421 CVEs Including Actively Exploited Zero-Day (CVE-2026-68820) and Multiple Critical RCEs: What changed Overall Patch Tuesday scope expanded from 400 to 421 CVEs (62 Critical vs. the 42 previously tracked); headline CVSS escalated 7.8 → 9.9 reflecting the newly reported CVE-2026-50481 (Azure AD elevation of privilege, CWE-471), d
- 2026-08-15 — Windows AFD.sys Zero-Day (CVE-2026-68820) Exploited by Lazarus Group to Deploy FudModule Rootkit v3.1 in 'Operation Dream Job' Defense-Sector Campaign: What changed No field escalations applied. The new report's severity_level (HIGH) and cvss_score (7.0) are both LOWER than the existing record's (CRITICAL / 7.8), so per escalation-only policy they are not applied. Exploitability (ACTIVE),
- 2026-08-13 — LegacyHive (CVE-2026-62832): Windows User Profile Service Zero-Day Patched in August 2026 Patch Tuesday: What changed No escalation to the overall threat record: existing CRITICAL/ACTIVE status reflects the Lazarus-exploited CVE-2026-68820 component and stands. The newer report is a deep dive specifically on the LegacyHive (CVE-2026-62832) com
- 2026-08-12 — Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) in Operation Dream Job Campaign: What changed No field escalations — severity, exploitability, status, and attribution confidence are unchanged. The report adds granular TTP and campaign-scope detail: a post-quantum ML-KEM (Kyber) key exchange used by MISTPEN's LPE loader
- 2026-08-12 — Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) to Deploy FudModule Rootkit Against Defense Firms: What changed No field escalation — severity/exploitability/status/attribution already match the existing CRITICAL/ACTIVE/ACTIVE/HIGH record. New indicators (1) 1 new behavioral IOC: the PDF trigger marker string SecurityPDF checks for befor
- 2026-08-12 — Microsoft August 2026 Patch Tuesday: Lazarus Group Exploits Windows AFD WinSock Zero-Day (CVE-2026-68820) to Deploy FudModule Rootkit, Plus Two Publicly Disclosed EoP Flaws: What changed No field-level escalation. Severity, exploitability, status, and attribution confidence are unchanged; the update adds forensic/technical granularity rather than altering the threat's assessed impact. New indicators (2) 2 new a
- 2026-08-12 — Microsoft August 2026 Patch Tuesday: Lazarus Exploits CVE-2026-68820 Zero-Day to Deploy FudModule Rootkit Amid 415 CVEs Patched (62 Critical): What changed No field escalations: the new report's severity (HIGH) and CVSS (7.0) are lower than the existing record's (CRITICAL / 7.8) and are not applied per the never-downgrade rule; exploitability, status, and attribution were already
- 2026-08-12 — Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) to Deploy FudModule Rootkit in Operation Dream Job: What changed No field escalations — the newer report's own severity (HIGH/CVSS 7.0) and impact are narrower than the CRITICAL/7.8 already on file, so nothing was downgraded. New indicators (7) 5 new file hashes (ForestTiger backdoor sample,
- 2026-08-12 — Microsoft August 2026 Patch Tuesday: 421 Vulnerabilities, 62 Critical, CVE-2026-68820 (AFD.sys) Exploited by Lazarus Group's FudModule Rootkit in Operation Dream Job: What changed No field escalations: severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and attribution_confidence (HIGH) were already at their maximum values in the existing record. What changed is depth and scope — the newer rep
Sources cited for Microsoft August 2026 Patch Tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
- CVE-2026-68820 (MSRC Security Update Guide)
- CVE-2026-62832 (MSRC Security Update Guide)
- CVE-2026-72971 (MSRC Security Update Guide)
- Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group G0032
- Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day
- Critical Windows 10, 11, and Server Zero-Day: 'LegacyHive' Exploit Enables Privilege Escalation via User Profile Service Vulnerability
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
- Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems
- LegacyHive: The Windows User Profile Service Bug That Loads Another User's Registry Hive Nightmare
- Nightmare Eclipse drops new Windows privilege escalation vulnerability
- LegacyHive: Video demo and analysis of Windows 0-day from NightmareEclipse
- LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised
- LegacyHive: The Windows Zero-Day That Loads Another User's Registry Hive
Detection coverage for TL-2026-1987
As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1987 across Splunk SPL, Microsoft KQL and Sigma, covering 72 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.