Microsoft Patches 400 Flaws: One Zero-Day Already in the Wild
Microsoft's August 2026 Patch Tuesday dropped yesterday with fixes for 400 security flaws, 42 of them critical. Three are zero-days. One, CVE-2026-68820, is already being exploited in attacks linked to North Korea's Lazarus group.
What's Being Exploited
The actively exploited flaw is a privilege escalation in the Windows WinSock driver (afd.sys). An attacker who already has basic access to a machine can escalate to SYSTEM level, giving them full control. Check Point's research shows Lazarus used it to deploy a kernel-level rootkit called FudModule, which makes the attacker effectively invisible to most endpoint security tools.
The other two zero-days (CVE-2026-62832 and CVE-2026-72971) were publicly disclosed before patches were ready, so exploit code is already circulating. Also in the critical pile: CVE-2026-62878, a Windows DNS buffer overflow that lets an unauthenticated attacker run code over the network without any user interaction.
| CVE | Component | Impact | Status |
|---|---|---|---|
| CVE-2026-68820 | Windows WinSock (afd.sys) | Privilege escalation to SYSTEM; FudModule rootkit deployment | Actively exploited |
| CVE-2026-62832 | Windows (undisclosed) | Zero-day; exploit code circulating | PoC public |
| CVE-2026-72971 | Windows (undisclosed) | Zero-day; exploit code circulating | PoC public |
| CVE-2026-62878 | Windows DNS Server | Unauthenticated RCE over network; no user interaction required | Critical |
What to Do
- If patching in-house, move the August updates to the front of the queue immediately; do not wait for a scheduled window.
- Prioritise CVE-2026-68820, CVE-2026-62832, CVE-2026-72971, and CVE-2026-62878 before other updates this cycle.
- If you outsource IT, ask your provider for a specific date the August patches will be applied, and get a specific answer, not "soon."
- Check endpoint detection tooling for signs of FudModule rootkit activity, particularly on machines with elevated privileges.
- If you're not sure whether your systems are patched, get in touch; we can check.
Why This Matters for Australian SMBs
We see a pattern across our Australian client base: the assumption that "we're too small for nation-state attacks" is exactly the gap groups like Lazarus exploit. They're not targeting you specifically; they're scanning for unpatched Windows machines, and yours shows up the same as everyone else's. Our managed patching service covers critical updates within 48 hours of release, so your business isn't sitting exposed while someone gets around to it.
Sources
Written by Michael Sacco, Head of Service Delivery, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.
Frequently Asked Questions: August 2026 Patch Tuesday
Not Sure If Your Systems Are Patched?
Our team can verify your patch status and apply the August updates within 48 hours. We also offer managed IT support that keeps your environment current without you having to track every advisory.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
