# Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)

> Microsoft's August 2026 Patch Tuesday fixed 400 vulnerabilities, including three zero-days: CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock (AFD.sys) actively exploited by the North Korean Lazarus Group to deploy its FudModule kernel-mode rootkit, and two publicly disclosed zero-days — CVE-2026-62832 ("LegacyHive", a Windows User Profile Service link-following flaw whose PoC was released a month earlier) and CVE-2026-72971 (Windows Container Isolation FS Filter Driver / unionfs.sys tampering). The release also addressed 42 Critical vulnerabilities (37 RCE, 5 EoP) across Windows and Azure components.

- **Published:** 2026-08-11T00:00:00Z
- **Last reviewed:** 2026-10-08T12:24:33.534Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1987
- **ID:** TL-2026-1987
- **Severity:** CRITICAL (CVSS 9.9)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** Lazarus Group (North Korea)
- **Detections:** 9 · **IOCs:** 72 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-68820, CVE-2026-62832, CVE-2026-72971, CVE-2026-62818, CVE-2026-68823, CVE-2026-50515, CVE-2026-62823, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789, CVE-2026-62878, CVE-2026-62815, CVE-2026-62819, CVE-2026-62889, CVE-2026-62893, CVE-2026-62824, CVE-2026-49163, CVE-2026-50481, CVE-2026-62869, CVE-2026-62911, CVE-2026-59115, CVE-2026-65665, CVE-2025-49113, CVE-2026-62737, CVE-2026-62816, CVE-2026-68804, CVE-2026-63526, CVE-2026-68794, CVE-2026-68816, CVE-2026-63518, CVE-2026-63525, CVE-2026-64907, CVE-2026-63515, CVE-2026-70130, CVE-2026-63532, CVE-2026-64898, CVE-2026-64903, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-65657, CVE-2026-62890, CVE-2026-62822, CVE-2026-64921, CVE-2026-62827, CVE-2026-70332, CVE-2026-55040, CVE-2026-63520, CVE-2026-62910, CVE-2026-62912, CVE-2026-62913, CVE-2026-62914, CVE-2026-62915, CVE-2026-65813

## Description

On August 11, 2026, Microsoft released its August Patch Tuesday update, resolving 400 vulnerabilities across its product line — a decrease from July 2026's record 570 but still far above historical norms, which Microsoft attributed in part to an internal AI-powered vulnerability discovery system surfacing additional flaws.

The headline item is CVE-2026-68820, a use-after-free (CWE-416) in AFD.sys, the Ancillary Function Driver for WinSock that is installed by default on every Windows system and provides kernel-mode support for the Winsock networking stack. The flaw lets an authorized local attacker win a race condition to escalate to SYSTEM privileges (CVSS 3.1 7.0, AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H). Check Point Research, publishing findings concurrently with the patch, attributed active in-the-wild exploitation of this flaw to the North Korean Lazarus Group, which used it to deploy FudModule, its purpose-built kernel-mode rootkit. Because AFD.sys ships by default, this exploitation required no separate Bring-Your-Own-Vulnerable-Driver (BYOVD) staging step of the kind Lazarus has previously used with third-party drivers. Microsoft credits Check Point researchers Moshe Marelus and David Driker with the discovery.

FudModule's broader tradecraft — documented across its evolving versions by researchers including Gen Digital — corrupts the exploited thread's PreviousMode field to gain a kernel read/write primitive (routed exclusively through NtWriteVirtualMemory to minimize telemetry), then uses that primitive to strip registry, object, process/thread/image-load, and image-verification kernel callbacks; unlink AV/EDR minifilter drivers; suppress Windows Filtering Platform callouts; zero ETW's active system logger list and disable roughly 95 ETW provider GUIDs; strip Protected Process Light (PPL) protection from security products (e.g., AhnLab's asdsvc.exe); and suspend threads inside Microsoft Defender, CrowdStrike Falcon, and HitmanPro via direct handle-table manipulation. The rootkit records which techniques executed successfully to a marker file historically named tem1245.tmp.

CVE-2026-62832 is an improper link-resolution flaw (CWE-59, CVSS 3.1 7.8) in the Windows User Profile Service (ProfSvc) that lets a low-privileged, authenticated attacker force the SYSTEM-level service to load another user's — potentially an administrator's — registry hive under the attacker's own profile, exposing that data or enabling further privilege escalation. This is the vulnerability behind "LegacyHive," a PoC independent researcher Nightmare Eclipse (MSNightmare) publicly released on July 15, 2026, roughly a month before Microsoft's fix. The exploit chains registry poisoning, object-manager symbolic links, and a TOCTOU race won via an opportunistic lock (oplock) on a decoy file to swap a symlink at the exact moment ProfSvc loads the target hive; it reportedly worked against fully patched Windows 10, Windows 11, and Windows Server (2016/2019/2022) systems with no interim Microsoft mitigation available prior to this release.

CVE-2026-72971 is a related-class improper link-resolution flaw (CWE-59, CVSS 3.1 5.5, high integrity impact) in unionfs.sys, the Windows Container Isolation FS Filter Driver that enforces isolation for Windows containers, affecting Windows 11 26H1 (x64/ARM64) builds prior to 10.0.28000.2704. Microsoft credits researchers identified as yhw and txz.

Beyond the three zero-days, the release fixed 42 Critical vulnerabilities (37 RCE, 5 EoP), including RCEs in Active Directory Certificate Services, Azure Confidential Ledger, Azure Service Bus, Windows DHCP Server, Windows DNS Server (four separate CVEs), Microsoft QUIC, Windows RRAS, Windows SSTP, Windows Deployment Services TFTP, and the Remote Desktop Client, plus Critical EoP/spoofing issues in Application Insights Profiler, Azure Active Directory, Azure Entra ID, Microsoft Exchange Server, and Microsoft Entra Provisioning Service.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1203 Exploitation for Client Execution
- T1611 Escape to Host
- T1014 Rootkit
- T1685 Disable or Modify Tools
- T1112 Modify Registry
- T1565 Data Manipulation
- T1566.002 Phishing
- T1204.002 User Execution
- T1059.003 Command and Scripting Interpreter
- T1068 Exploitation for Privilege Escalation
- T1055.001 Process Injection
- T1562.001 Impair Defenses
- T1082 System Information Discovery
- T1057 Process Discovery
- T1083 File and Directory Discovery
- T1113 Screen Capture
- T1105 Ingress Tool Transfer
- T1071 Application Layer Protocol
- T1041 Exfiltration Over C2 Channel
- T1584.004 Compromise Infrastructure
- T1505.003 Server Software Component
- T1574.002 Hijack Execution Flow
- T1620 Reflective Code Loading
- T1562.006 Impair Defenses
- T1036.005 Masquerading
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1102.002 Web Service
- T1005 Data from Local System
- T1566.001 Phishing
- T1562.002 Impair Defenses
- T1553.002 Subvert Trust Controls
- T1071.001 Application Layer Protocol
- T1140 Deobfuscate/Decode Files or Information
- T1560 Archive Collected Data
- T1567.002 Exfiltration Over Web Service
- T1583.001 Acquire Infrastructure: Domains
- T1553.006 Subvert Trust Controls: Code Signing Policy Modification

## Sources

- [Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days](https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/)
- [CVE-2026-68820 (MSRC Security Update Guide)](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820)
- [CVE-2026-62832 (MSRC Security Update Guide)](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832)
- [CVE-2026-72971 (MSRC Security Update Guide)](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971)
- [Lazarus Group, Labyrinth Chollima, HIDDEN COBRA, Guardians of Peace, ZINC, NICKEL ACADEMY, Diamond Sleet, Group G0032](https://attack.mitre.org/groups/G0032/)
- [Lazarus and the FudModule Rootkit: Beyond BYOVD with an Admin-to-Kernel Zero-Day](https://www.gendigital.com/blog/insights/research/lazarus-and-the-fudmodule-rootkit-beyond-byovd-with-an-admin-to-kernel-zero-day)
- [Critical Windows 10, 11, and Server Zero-Day: 'LegacyHive' Exploit Enables Privilege Escalation via User Profile Service Vulnerability](https://www.rescana.com/post/critical-windows-10-11-and-server-zero-day-legacyhive-exploit-enables-privilege-escalation-via-user-profile-service-vuln)
- [Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday](https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html)
- [Chaotic Eclipse Unveils LegacyHive Exploit Affecting Fully Patched Windows Systems](https://securityaffairs.com/195418/hacking/chaotic-eclipse-unveils-legacyhive-exploit-affecting-fully-patched-windows-systems.html)
- [LegacyHive: The Windows User Profile Service Bug That Loads Another User's Registry Hive Nightmare](https://socprime.com/active-threats/legacyhive-the-windows-user-profile-service-bug-that-loads-another-users-registry-hive-nightmare/)
- [Nightmare Eclipse drops new Windows privilege escalation vulnerability](https://cybernews.com/security/nightmare-eclipse-windows-legacyhive-privilege-escalation-bug/)
- [LegacyHive: Video demo and analysis of Windows 0-day from NightmareEclipse](https://www.threatlocker.com/blog/legacyhive-video-demo-and-analysis-of-windows-0-day-from-nightmareeclipse)
- [LegacyHive: 'Bone-shattering' zero-day from Microsoft's serial tormentor not the haymaker that was promised](https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723)
- [LegacyHive: The Windows Zero-Day That Loads Another User's Registry Hive](https://purplesec.org/blog/legacyhive-windows-zero-day/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1987
