Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for Microsoft August 2026 Patch Tuesday with 400 flaws and 3 zero-days including one actively exploited

Microsoft Patches 400 Flaws: One Zero-Day Already in the Wild

Microsoft's August 2026 Patch Tuesday dropped yesterday with fixes for 400 security flaws, 42 of them critical. Three are zero-days. One, CVE-2026-68820, is already being exploited in attacks linked to North Korea's Lazarus group.

Active exploitation confirmed: CVE-2026-68820 (Windows WinSock privilege escalation) is being used in live Lazarus group attacks. Apply the August patches immediately.

What's Being Exploited

The actively exploited flaw is a privilege escalation in the Windows WinSock driver (afd.sys). An attacker who already has basic access to a machine can escalate to SYSTEM level, giving them full control. Check Point's research shows Lazarus used it to deploy a kernel-level rootkit called FudModule, which makes the attacker effectively invisible to most endpoint security tools.

The other two zero-days (CVE-2026-62832 and CVE-2026-72971) were publicly disclosed before patches were ready, so exploit code is already circulating. Also in the critical pile: CVE-2026-62878, a Windows DNS buffer overflow that lets an unauthenticated attacker run code over the network without any user interaction.

CVE Component Impact Status
CVE-2026-68820 Windows WinSock (afd.sys) Privilege escalation to SYSTEM; FudModule rootkit deployment Actively exploited
CVE-2026-62832 Windows (undisclosed) Zero-day; exploit code circulating PoC public
CVE-2026-72971 Windows (undisclosed) Zero-day; exploit code circulating PoC public
CVE-2026-62878 Windows DNS Server Unauthenticated RCE over network; no user interaction required Critical

What to Do

  • If patching in-house, move the August updates to the front of the queue immediately; do not wait for a scheduled window.
  • Prioritise CVE-2026-68820, CVE-2026-62832, CVE-2026-72971, and CVE-2026-62878 before other updates this cycle.
  • If you outsource IT, ask your provider for a specific date the August patches will be applied, and get a specific answer, not "soon."
  • Check endpoint detection tooling for signs of FudModule rootkit activity, particularly on machines with elevated privileges.
  • If you're not sure whether your systems are patched, get in touch; we can check.

Why This Matters for Australian SMBs

We see a pattern across our Australian client base: the assumption that "we're too small for nation-state attacks" is exactly the gap groups like Lazarus exploit. They're not targeting you specifically; they're scanning for unpatched Windows machines, and yours shows up the same as everyone else's. Our managed patching service covers critical updates within 48 hours of release, so your business isn't sitting exposed while someone gets around to it.

Related guide: Cybersecurity for Sydney SMBs: our complete guide to protecting your business from cyber threats.

Written by Michael Sacco, Head of Service Delivery, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.


Frequently Asked Questions: August 2026 Patch Tuesday

CVE-2026-68820 is a privilege escalation vulnerability in the Windows WinSock driver (afd.sys). It allows an attacker with basic access to a Windows machine to escalate their privileges to SYSTEM level, giving them full control. It is being prioritised because it is actively exploited in the wild by the Lazarus group, a North Korean state-sponsored threat actor, to deploy the FudModule kernel-level rootkit.
FudModule is a kernel-level rootkit deployed by Lazarus group following successful exploitation of CVE-2026-68820. Once installed, it operates at the kernel level, making it effectively invisible to most standard endpoint detection and antivirus tools. Patching CVE-2026-68820 prevents the initial privilege escalation that enables FudModule deployment. If you suspect a machine may already be compromised, a professional forensic review is recommended before patching alone.
There are three zero-days in the August 2026 Patch Tuesday release. CVE-2026-68820 (WinSock privilege escalation) is actively exploited. CVE-2026-62832 and CVE-2026-72971 were publicly disclosed before patches were available, meaning exploit code is already circulating. All three should be patched immediately.
Given active exploitation, the four priority flaws (CVE-2026-68820, CVE-2026-62832, CVE-2026-72971, and CVE-2026-62878) should be patched within 24 to 48 hours. Waiting for a scheduled maintenance window is not appropriate for actively exploited zero-days. All IT Services applies critical patches to managed clients within 48 hours of release as standard.

Not Sure If Your Systems Are Patched?

Our team can verify your patch status and apply the August updates within 48 hours. We also offer managed IT support that keeps your environment current without you having to track every advisory.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →