Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971) — Threadlinqs Intelligence
As of 2026-08-20, Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971) is a critical-severity vulnerability threat attributed to Lazarus Group (North Korea (DPRK)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 70 indicators of compromise.
Threat ID: TL-2026-1987 · Severity: CRITICAL · CVSS: 9.9 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-08-20 · 9 updates · revalidated 9× · latest source
Attribution: Lazarus Group · North Korea (DPRK) · ESPIONAGE
Microsoft's August 2026 Patch Tuesday fixed 400 vulnerabilities, including three zero-days: CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock (AFD.sys) actively
On August 11, 2026, Microsoft released its August Patch Tuesday update, resolving 400 vulnerabilities across its product line — a decrease from July 2026's record 570 but still far above historical norms, which Microsoft attributed in part to an internal AI-powered vulnerability discovery system surfacing additional flaws.
The headline item is CVE-2026-68820, a use-after-free (CWE-416) in AFD.sys, the Ancillary Function Driver for WinSock that is installed by default on every Windows system and provides kernel-mode support for the Winsock networking stack. The flaw lets an authorized local attacker win a race condition to escalate to SYSTEM privileges (CVSS 3.1 7.0, AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Check Point Research, publishing findings concurrently with the patch, attributed active in-the-wild exploitation of this flaw to the North Korean Lazarus Group, which used it to deploy FudModule, its purpose-built kernel-mode rootkit. Because AFD.sys ships by default, this exploitation required no separate Bring-Your-Own-Vulnerable-Driver (BYOVD) staging step of the kind Lazarus has previously used with third-party drivers. Microsoft credits Check Point researchers Moshe Marelus and David Driker with the discovery.
FudModule's broader tradecraft — documented across its evolving versions by researchers including Gen Digital — corrupts the exploited thread's PreviousMode field to gain a kernel read/write primitive (routed exclusively through NtWriteVirtualMemory to minimize telemetry), then uses that primitive to strip registry, object, process/thread/image-load, and image-verification kernel callbacks; unlink AV/EDR minifilter drivers; suppress Windows Filtering Platform callouts; zero ETW's active system logger list and disable roughly 95 ETW provider GUIDs; strip Protected Process Light (PPL) protection from security products (e.g., AhnLab's asdsvc.exe); and suspend threads inside Microsoft Defender, CrowdStrike Falcon, and HitmanPro via direct handle-table manipulation. The rootkit records which techniques executed successfully to a marker file historically named tem1245.tmp.
CVE-2026-62832 is an improper link-resolution flaw (CWE-59, CVSS 3.1 7.8) in the Windows User Profile Service (ProfSvc) that lets a low-privileged, authenticated attacker force the SYSTEM-level service to load another user's — potentially an administrator's — registry hive under the attacker's own profile, exposing that data or enabling further privilege escalation. This is the vulnerability behind "LegacyHive," a PoC independent researcher Nightmare Eclipse (MSNightmare) publicly released on July 15, 2026, roughly a month before Microsoft's fix. The exploit chains registry poisoning, object-manager symbolic links, and a TOCTOU race won via an opportunistic lock (oplock) on a decoy file to swap a symlink at the exact moment ProfSvc loads the target hive; it reportedly worked against fully patched Windows 10, Windows 11, and Windows Server (2016/2019/2022) systems with no interim Microsoft mitigation available prior to this release.
CVE-2026-72971 is a related-class improper link-resolution flaw (CWE-59, CVSS 3.1 5.5, high integrity impact) in unionfs.sys, the Windows Container Isolation FS Filter Driver that enforces isolation for Windows containers, affecting Windows 11 26H1 (x64/ARM64) builds prior to 10.0.28000.2704. Microsoft credits researchers identified as yhw and txz.
Beyond the three zero-days, the release fixed 42 Critical vulnerabilities (37 RCE, 5 EoP), including RCEs in Active Directory Certificate Services, Azure Confidential Ledger, Azure Service Bus, Windows DHCP Server, Windows DNS Server (four separate CVEs), Microsoft QUIC, Windows RRAS, Windows SSTP, Windows Deployment Services TFTP, and the Remote Desktop Client, plus Critical EoP/spoofing issues in Application Insights Profiler, Azure Active Directory, Azure Entra ID, Microsoft Exchange Server, and Microsoft Entra Provisioning Service.
Weaknesses (CWE)
CWE-416, CWE-59, CWE-502, CWE-122, CWE-822, CWE-121, CWE-471, CWE-415, CWE-294, CWE-918
Target sectors: financial services, banking, defense, aerospace, technology, critical infrastructure electric grid, entertainment
Target regions: Global, united states of america, Europe, Latin America
Update History
- 2026-08-20 — Microsoft August 2026 Patch Tuesday — 421 CVEs Including Actively Exploited Zero-Day (CVE-2026-68820) and Multiple Critical RCEs: What changed Overall Patch Tuesday scope expanded from 400 to 421 CVEs (62 Critical vs. the 42 previously tracked); headline CVSS escalated 7.8 → 9.9 reflecting the newly reported CVE-2026-50481 (Azure AD elevation of privilege, CWE-471), d
- 2026-08-15 — Windows AFD.sys Zero-Day (CVE-2026-68820) Exploited by Lazarus Group to Deploy FudModule Rootkit v3.1 in 'Operation Dream Job' Defense-Sector Campaign: What changed No field escalations applied. The new report's severity_level (HIGH) and cvss_score (7.0) are both LOWER than the existing record's (CRITICAL / 7.8), so per escalation-only policy they are not applied. Exploitability (ACTIVE),
- 2026-08-13 — LegacyHive (CVE-2026-62832): Windows User Profile Service Zero-Day Patched in August 2026 Patch Tuesday: What changed No escalation to the overall threat record: existing CRITICAL/ACTIVE status reflects the Lazarus-exploited CVE-2026-68820 component and stands. The newer report is a deep dive specifically on the LegacyHive (CVE-2026-62832) com
- 2026-08-12 — Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) in Operation Dream Job Campaign: What changed No field escalations — severity, exploitability, status, and attribution confidence are unchanged. The report adds granular TTP and campaign-scope detail: a post-quantum ML-KEM (Kyber) key exchange used by MISTPEN's LPE loader
- 2026-08-12 — Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) to Deploy FudModule Rootkit Against Defense Firms: What changed No field escalation — severity/exploitability/status/attribution already match the existing CRITICAL/ACTIVE/ACTIVE/HIGH record. New indicators (1) 1 new behavioral IOC: the PDF trigger marker string SecurityPDF checks for befor
- 2026-08-12 — Microsoft August 2026 Patch Tuesday: Lazarus Group Exploits Windows AFD WinSock Zero-Day (CVE-2026-68820) to Deploy FudModule Rootkit, Plus Two Publicly Disclosed EoP Flaws: What changed No field-level escalation. Severity, exploitability, status, and attribution confidence are unchanged; the update adds forensic/technical granularity rather than altering the threat's assessed impact. New indicators (2) 2 new a
- 2026-08-12 — Microsoft August 2026 Patch Tuesday: Lazarus Exploits CVE-2026-68820 Zero-Day to Deploy FudModule Rootkit Amid 415 CVEs Patched (62 Critical): What changed No field escalations: the new report's severity (HIGH) and CVSS (7.0) are lower than the existing record's (CRITICAL / 7.8) and are not applied per the never-downgrade rule; exploitability, status, and attribution were already
- 2026-08-12 — Lazarus Group Exploits Windows AFD.sys Zero-Day (CVE-2026-68820) to Deploy FudModule Rootkit in Operation Dream Job: What changed No field escalations — the newer report's own severity (HIGH/CVSS 7.0) and impact are narrower than the CRITICAL/7.8 already on file, so nothing was downgraded. New indicators (7) 5 new file hashes (ForestTiger backdoor sample,
- 2026-08-12 — Microsoft August 2026 Patch Tuesday: 421 Vulnerabilities, 62 Critical, CVE-2026-68820 (AFD.sys) Exploited by Lazarus Group's FudModule Rootkit in Operation Dream Job: What changed No field escalations: severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), and attribution_confidence (HIGH) were already at their maximum values in the existing record. What changed is depth and scope — the newer rep
References
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
- CVE-2026-68820 (MSRC Security Update Guide)
- CVE-2026-62832 (MSRC Security Update Guide)
- CVE-2026-72971 (MSRC Security Update Guide)
- Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group G0032
- Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day
- Critical Windows 10, 11, and Server Zero-Day: 'LegacyHive' Exploit Enables Privilege Escalation via User Profile Service Vulnerability
- Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
- Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems
- LegacyHive: The Windows User Profile Service Bug That Loads Another User's Registry Hive Nightmare
- Nightmare Eclipse drops new Windows privilege escalation vulnerability
- LegacyHive: Video demo and analysis of Windows 0-day from NightmareEclipse
- LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised
- LegacyHive: The Windows Zero-Day That Loads Another User's Registry Hive
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 70 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-68820, CVE-2026-62832, CVE-2026-72971, CVE-2026-62818, CVE-2026-68823, CVE-2026-50515, CVE-2026-62823, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789, T1190, T1078, T1203, T1611, T1014, T1685, T1112, T1565, T1566.002, T1204.002