Threat reportVulnerabilityTL-2026-1987

Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)

criticalACTIVE

Microsoft August 2026 Patch Tuesday (TL-2026-1987), also tracked as LegacyHive, is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-08-11 and last reviewed 2026-10-08. It is attributed to Lazarus Group (North Korea) with high confidence, affects Microsoft Windows Ancillary Function Driver for WinSock (AFD.sys), references 54 CVEs (CVE-2026-68820, CVE-2026-62832, CVE-2026-72971), maps to 64 MITRE ATT&CK techniques (T1005, T1012, T1014), and is covered by 9 detection rules and 72 indicators of compromise.

CVSS
9.9/10Critical
CVEs
54Referenced vulnerabilities
Techniques
64MITRE ATT&CK
Actors
1Lazarus Group
Detection rules
9SPL · KQL · Sigma
IOCs
72Indicators of compromise

Key facts for TL-2026-1987

Threat ID
TL-2026-1987
Also known as
LegacyHive
Severity
CRITICAL
CVSS
9.9 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
Lazarus Group
Attribution confidence
HIGH
Nation-state nexus
North Korea
Motivation
ESPIONAGE
Target sectors
financial services, banking, defense, aerospace, technology, critical infrastructure electric grid, entertainment
Target regions
Global, united states of america, Europe, Latin America
Detection rules
9
Indicators of compromise
72
Updates
2026-10-08 · 10 updates · revalidated 10× · latest source

Malware and tooling in Microsoft August 2026 Patch Tuesday

Malware and tooling: FudModule, CVE-2026-68820 AFD.sys use-after-free exploit, LegacyHive PoC exploit

How Microsoft August 2026 Patch Tuesday works

Microsoft's August 2026 Patch Tuesday fixed 400 vulnerabilities, including three zero-days: CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock (AFD.sys) actively exploited by the North Korean Lazarus Group to deploy its FudModule kernel-mode rootkit, and two publicly disclosed zero-days — CVE-2026-62832 ("LegacyHive", a Windows User Profile Service link-following flaw whose PoC was released a month earlier) and CVE-2026-72971 (Windows Container Isolation FS Filter Driver / unionfs.sys tampering). The release also addressed 42 Critical vulnerabilities (37 RCE, 5 EoP) across Windows and Azure components.

On August 11, 2026, Microsoft released its August Patch Tuesday update, resolving 400 vulnerabilities across its product line — a decrease from July 2026's record 570 but still far above historical norms, which Microsoft attributed in part to an internal AI-powered vulnerability discovery system surfacing additional flaws.

The headline item is CVE-2026-68820, a use-after-free (CWE-416) in AFD.sys, the Ancillary Function Driver for WinSock that is installed by default on every Windows system and provides kernel-mode support for the Winsock networking stack. The flaw lets an authorized local attacker win a race condition to escalate to SYSTEM privileges (CVSS 3.1 7.0, AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Check Point Research, publishing findings concurrently with the patch, attributed active in-the-wild exploitation of this flaw to the North Korean Lazarus Group, which used it to deploy FudModule, its purpose-built kernel-mode rootkit. Because AFD.sys ships by default, this exploitation required no separate Bring-Your-Own-Vulnerable-Driver (BYOVD) staging step of the kind Lazarus has previously used with third-party drivers. Microsoft credits Check Point researchers Moshe Marelus and David Driker with the discovery.

FudModule's broader tradecraft — documented across its evolving versions by researchers including Gen Digital — corrupts the exploited thread's PreviousMode field to gain a kernel read/write primitive (routed exclusively through NtWriteVirtualMemory to minimize telemetry), then uses that primitive to strip registry, object, process/thread/image-load, and image-verification kernel callbacks; unlink AV/EDR minifilter drivers; suppress Windows Filtering Platform callouts; zero ETW's active system logger list and disable roughly 95 ETW provider GUIDs; strip Protected Process Light (PPL) protection from security products (e.g., AhnLab's asdsvc.exe); and suspend threads inside Microsoft Defender, CrowdStrike Falcon, and HitmanPro via direct handle-table manipulation. The rootkit records which techniques executed successfully to a marker file historically named tem1245.tmp.

CVE-2026-62832 is an improper link-resolution flaw (CWE-59, CVSS 3.1 7.8) in the Windows User Profile Service (ProfSvc) that lets a low-privileged, authenticated attacker force the SYSTEM-level service to load another user's — potentially an administrator's — registry hive under the attacker's own profile, exposing that data or enabling further privilege escalation. This is the vulnerability behind "LegacyHive," a PoC independent researcher Nightmare Eclipse (MSNightmare) publicly released on July 15, 2026, roughly a month before Microsoft's fix. The exploit chains registry poisoning, object-manager symbolic links, and a TOCTOU race won via an opportunistic lock (oplock) on a decoy file to swap a symlink at the exact moment ProfSvc loads the target hive; it reportedly worked against fully patched Windows 10, Windows 11, and Windows Server (2016/2019/2022) systems with no interim Microsoft mitigation available prior to this release.

CVE-2026-72971 is a related-class improper link-resolution flaw (CWE-59, CVSS 3.1 5.5, high integrity impact) in unionfs.sys, the Windows Container Isolation FS Filter Driver that enforces isolation for Windows containers, affecting Windows 11 26H1 (x64/ARM64) builds prior to 10.0.28000.2704. Microsoft credits researchers identified as yhw and txz.

Beyond the three zero-days, the release fixed 42 Critical vulnerabilities (37 RCE, 5 EoP), including RCEs in Active Directory Certificate Services, Azure Confidential Ledger, Azure Service Bus, Windows DHCP Server, Windows DNS Server (four separate CVEs), Microsoft QUIC, Windows RRAS, Windows SSTP, Windows Deployment Services TFTP, and the Remote Desktop Client, plus Critical EoP/spoofing issues in Application Insights Profiler, Azure Active Directory, Azure Entra ID, Microsoft Exchange Server, and Microsoft Entra Provisioning Service.

MITRE ATT&CK techniques used in TL-2026-1987

Collection

T1005 Data from Local System; T1074.001 Data Staged; T1113 Screen Capture; T1560 Archive Collected Data; T1560.002 Archive Collected Data: Archive via Library

Discovery

T1012 Query Registry; T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087.001 Account Discovery

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1036.005 Masquerading; T1036.008 Masquerading: Masquerade File Type; T1055 Process Injection; T1055.001 Process Injection; T1070.001 Indicator Removal: Clear Windows Event Logs; T1078.001 Valid Accounts: Default Accounts; T1140 Deobfuscate/Decode Files or Information; T1218.001 Signed Binary Proxy Execution: Msiexec; T1553.002 Subvert Trust Controls; T1553.006 Subvert Trust Controls: Code Signing Policy Modification; T1562.001 Impair Defenses; T1562.002 Impair Defenses; T1562.006 Impair Defenses; T1574.002 Hijack Execution Flow; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1537 Transfer Data to Cloud Account; T1567.002 Exfiltration Over Web Service

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204.002 User Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1543.003 Create or Modify System Process: Windows Service; T1611 Escape to Host

Command and Control

T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1090 Proxy; T1090.003 Proxy: Multi-hop Proxy; T1102.002 Web Service; T1105 Ingress Tool Transfer; T1573 Encrypted Channel; T1573.001 Encrypted Channel: Symmetric Cryptography

Initial Access

T1078 Valid Accounts; T1078.003 Valid Accounts; T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.001 Phishing; T1566.002 Phishing

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Persistence

T1505.003 Server Software Component; T1547 Boot or Logon Autostart Execution; T1547.001 Boot or Logon Autostart Execution

Credential Access

T1550 Use Alternate Authentication Material; T1552.001 Unsecured Credentials; T1552.002 Unsecured Credentials

Impact

T1565 Data Manipulation

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1584.004 Compromise Infrastructure

Affected products and versions in Microsoft August 2026 Patch Tuesday

  • Microsoft — Windows Ancillary Function Driver for WinSock (AFD.sys)
    Vulnerable versions: Windows 10 1607/1809/21H2/22H2; Windows 11 23H2/24H2/25H2/26H1; Windows Server 2012-2025 (all 32-bit, x64, ARM64 builds)
    Fixed in: Microsoft August 2026 cumulative security update
  • Microsoft — Windows User Profile Service (ProfSvc)
    Vulnerable versions: Windows 10 21H2/22H2; Windows 11 23H2/24H2/25H2/26H1; Windows Server 2022/2025
    Fixed in: Microsoft August 2026 cumulative security update
  • Microsoft — Windows Container Isolation FS Filter Driver (unionfs.sys)
    Vulnerable versions: Windows 11 26H1 (x64, ARM64) prior to build 10.0.28000.2704
    Fixed in: Windows 11 26H1 build 10.0.28000.2704 and later

Remediation for Microsoft August 2026 Patch Tuesday

Patches

  • Microsoft August 2026 Patch Tuesday cumulative update resolving CVE-2026-68820 (AFD.sys use-after-free EoP)
  • Microsoft August 2026 cumulative update resolving CVE-2026-62832 (Windows User Profile Service link-following EoP / LegacyHive)
  • Microsoft August 2026 cumulative update resolving CVE-2026-72971 (unionfs.sys link-following tampering), Windows 11 26H1 build 10.0.28000.2704 and later

Immediate actions

  • Apply Microsoft's August 2026 cumulative security updates addressing CVE-2026-68820, CVE-2026-62832, and CVE-2026-72971 immediately, prioritizing any system where AFD.sys exploitation may already be underway.
  • Hunt for FudModule rootkit indicators: unexpected thread suspensions on MsMpEng.exe/CSFalconService.exe/HitmanPro processes, mass-disabled ETW providers, zeroed EtwpActiveSystemLoggers, and removed registry/object/process-thread-image kernel callbacks.
  • Deploy and keep current Microsoft's Vulnerable Driver Blocklist and enable Hypervisor-protected Code Integrity (HVCI) where hardware supports it to raise the bar against kernel driver/UAF exploitation.
  • Audit for anomalous Windows User Profile Service (ProfSvc) activity — unexpected registry hive loads under non-owning user profiles — as an interim detection for LegacyHive-class exploitation.

Workarounds

  • No official Microsoft workaround was published for CVE-2026-62832 (LegacyHive) between its July 15, 2026 public PoC disclosure and the August 11, 2026 patch; the interim mitigation was monitoring for anomalous ProfSvc hive-load events.
  • Restrict standard-user code execution on systems handling sensitive administrator sessions to reduce exposure to the local, authenticated-user exploitation vector shared by CVE-2026-68820, CVE-2026-62832, and CVE-2026-72971.

Longer-term hardening

  • Adopt kernel-resilient EDR telemetry (e.g., independent hypervisor-based sensors) that survives callback-removal and handle-table-manipulation style evasion used by FudModule.
  • Track public PoC disclosures for unpatched Windows internals bugs (LegacyHive-class link-following/TOCTOU races) and apply interim monitoring pending official patches, since standard privilege boundaries do not mitigate them.
  • Restrict local logon and application-execution rights on high-value endpoints to reduce exposure to the shared local, low-privilege prerequisite (PR:L, local AV) across all three zero-days.
  • Prioritize patching of the 42 Critical RCE/EoP flaws in this release on internet- and Azure-facing services (AD CS, DNS/DHCP/RRAS/SSTP, Azure Service Bus, Azure Confidential Ledger) given their network-reachable attack surface.

CVEs associated with Microsoft August 2026 Patch Tuesday

Weaknesses (CWE) in Microsoft August 2026 Patch Tuesday

CWE-416, CWE-59, CWE-502, CWE-122, CWE-822, CWE-121, CWE-471, CWE-415, CWE-294, CWE-918

Timeline of Microsoft August 2026 Patch Tuesday

Showing the 20 most recent tracked events.

  • ACROS Security (0Patch), led by CEO Mitja Kolsek, releases a free unofficial micropatch for LegacyHive covering Windows 10 2004+ and Windows Server 2022+, redirecting the exploit to load a temporary profile hive instead of the targeted user's real hive.
  • Check Point Research (Moshe Marelus, David Driker) reports the afd.sys use-after-free to Microsoft Security Response Center.
  • Microsoft confirms the CVE-2026-68820 vulnerability report.
  • Microsoft assigns CVE-2026-68820 to the confirmed afd.sys use-after-free.
  • A Chinese-language proof-of-concept for CVE-2026-62737 (Windows Kernel untrusted pointer dereference, CVSS 7.8) is published.
  • CVE-2026-62911 (Exchange Server capture-replay elevation of privilege) is publicly disclosed after a live Pwn2Own Berlin demonstration; ZDI advises treating exploitation as likely despite Microsoft's 'Less Likely' rating.
  • Microsoft's advisory and Patch Tuesday press coverage clarify CVE-2026-62832 is 'publicly disclosed' with exploitation 'more likely,' distinct from CVE-2026-68820 (the afd.sys use-after-free), which is the single zero-day Microsoft confirms as actively exploited in the same batch; CVE-2026-62832 is absent from the CISA KEV catalog as of this release.
  • Cisco Talos and Zero Day Initiative publish independent Patch Tuesday technical reviews covering the flagged CVEs and Snort/detection coverage.
  • Check Point Research publishes 'Shattering the Dream,' detailing the CVE-2026-68820 exploit chain, FudModule v3.1, the SecurityPDF lure, and the Troy/MISTPEN/RelayShell tooling of a resurgent Operation Dream Job campaign.
  • CISA adds CVE-2026-68820 to the Known Exploited Vulnerabilities catalog with a remediation due date of 2026-08-25.
  • BleepingComputer publishes coverage summarizing the August 2026 Patch Tuesday release, the three zero-days, and Lazarus's exploitation of CVE-2026-68820.
  • Check Point Research publishes findings, released concurrently with the patch, attributing in-the-wild exploitation of CVE-2026-68820 to the North Korean Lazarus Group, which used the flaw to deploy its FudModule kernel-mode rootkit.
  • CVE-2026-72971 (Windows Container Isolation FS Filter Driver / unionfs.sys tampering) is published, credited to researchers identified as yhw and txz.
  • CVE-2026-62832 (Windows User Profile Service link-following EoP, the LegacyHive flaw) is formally published, matching the July 2026 public PoC.
  • CVE-2026-68820 (Windows AFD.sys use-after-free elevation of privilege) is published, credited to Check Point researchers Moshe Marelus and David Driker.
  • Microsoft ships its August 2026 Patch Tuesday, fixing 400 vulnerabilities across its product line, including three zero-days and 42 Critical-rated flaws (37 RCE, 5 EoP).
  • BleepingComputer and other outlets publish dedicated coverage of the Lazarus Group AFD.sys/FudModule campaign against defense firms, a day after the initial Patch-Tuesday-focused reporting.
  • CISA adds CVE-2026-55040 (SharePoint JWT auth bypass) to the Known Exploited Vulnerabilities catalog based on evidence of active exploitation following PoC publication.
  • CISA BOD-mandated remediation deadline for CVE-2026-68820 per the KEV catalog entry.
  • Upcoming end-of-life milestones tied to this release: Windows 11 24H2 Home & Pro end of servicing, Windows Server 2012/2012 R2 ESU expires, Office 2021/LTSC 2021 out of support, Exchange Server 2016/2019 enters permanent unsupported state.

Update history for TL-2026-1987

Sources cited for Microsoft August 2026 Patch Tuesday

Detection coverage for TL-2026-1987

As of 2026-10-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1987 across Splunk SPL, Microsoft KQL and Sigma, covering 72 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
72 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats