TL;DR — Key Takeaways
- Microsoft’s August Patch Tuesday addressed roughly 400 vulnerabilities, with the broader August total reaching 421 when earlier fixes are included.
- CVE-2026-68820 was already being exploited in attacks linked to North Korea’s Lazarus group before Microsoft released a patch.
- Attackers used the Windows privilege-escalation flaw to gain SYSTEM-level access and deploy the FudModule kernel rootkit.
Microsoft has released one of its largest monthly security updates, fixing about 400 vulnerabilities in its August Patch Tuesday release, including a Windows flaw already exploited in attacks linked to North Korea’s Lazarus hacking group.
The update includes 42 vulnerabilities rated Critical. Of these, 37 could enable remote code execution and five could allow attackers to gain higher system privileges. Across the August release, Microsoft addressed 176 elevation-of-privilege flaws, 110 remote-code-execution vulnerabilities, 86 information-disclosure issues, 21 spoofing vulnerabilities, 12 denial-of-service flaws, 11 security-feature bypasses and four tampering vulnerabilities.
The total reaches 421 when security fixes released earlier in August for products including Microsoft Office, Teams and Entra are included.
Key Focus for Enterprise Security
For enterprise IT teams, one vulnerability warrants particular attention: CVE-2026-68820, an elevation-of-privilege flaw affecting the Windows Ancillary Function Driver for WinSock. Microsoft has confirmed that the vulnerability was exploited before a patch was available.
Check Point researchers connected the attacks to Lazarus, the name commonly used for a collection of North Korean cyber operations. The attackers used CVE-2026-68820 to deploy a new version of FudModule, a kernel-level rootkit associated with previous Lazarus campaigns.
The campaign used fake employment opportunities to target victims. Once malicious code was running on a Windows machine, the vulnerability could provide SYSTEM privileges, giving the attacker far greater control over the endpoint.
This combination of social engineering and a Windows kernel vulnerability illustrates why privilege-escalation flaws can pose a serious enterprise threat even when an attacker must first gain local access. An initial compromise can provide a foothold, then elevated privileges could enable an attacker to interfere with security controls and establish persistence.
Beyond the actively exploited CVE-2026-68820, Microsoft patched two other zero-day vulnerabilities that had been publicly disclosed but were not reported as exploited. CVE-2026-62832 affects Windows User Profile Service and could allow an attacker to access another user’s registry data and potentially gain administrator privileges. The flaw corresponds with the LegacyHive technique publicly demonstrated in July.
A third zero-day, CVE-2026-72971, affects the Windows Container Isolation file-system filter driver and could enable an authenticated local attacker to tamper with files.
Large Security Releases to Continue
The sheer size of recent Microsoft security releases is creating another challenge for enterprise IT admins. August follows a July Patch Tuesday release that fixed roughly 570 vulnerabilities.
Microsoft expects large security releases to continue, in part because AI is speeding up vulnerability research. The company has said AI is shortening the period required to discover and exploit software weaknesses, potentially reducing a process that once took weeks to mere hours.
Microsoft is also using AI for defense. Its MDASH vulnerability-discovery platform coordinates more than 100 specialized AI agents to examine software for security weaknesses. Microsoft said the technology contributed to finding 16 vulnerabilities released in May and has been expanded across products and technologies including Windows, Azure, Hyper-V, Active Directory and identity services.
In response to the faster vulnerability cycle, Microsoft is pushing customers toward more aggressive patching. The company recommends a deferral period of less than three days for Windows quality updates containing security fixes, with deadlines of zero or one day and a grace period no longer than two days.
For enterprise security pros, this creates a difficult operational balance. Large monthly updates must still be tested against business applications and infrastructure, yet long testing cycles leave known vulnerabilities exposed. The August release makes that risk tangible. One Windows flaw was already being used in an active attack campaign before Microsoft patched it.

