News Room
16
Share
Microsoft August 2026 Patch Tuesday: Critical AFD.sys Zero-Day Exploited by Lazarus Group
criticalZero-Day Exploits

Microsoft August 2026 Patch Tuesday: Critical AFD.sys Zero-Day Exploited by Lazarus Group

Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities, including a critical zero-day in the Windows AFD.sys driver (CVE-2026-68820) currently being exploited by the Lazarus Group to deploy rootkits.

12 August 2026Last updated 18 August 20264 min readBleepingComputer
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-68820
Source:
BleepingComputer
Read Time:
4 min

Executive Summary

On August 11, 2026, Microsoft released its monthly security updates, addressing a massive total of 421 vulnerabilities across its ecosystem. Most notably, the release includes a fix for CVE-2026-68820, a high-severity elevation of privilege vulnerability in the Ancillary Function Driver for WinSock (afd.sys) that has been confirmed as actively exploited in the wild.

Threat Analysis

Intelligence reports indicate that the Lazarus Group, a sophisticated nation-state actor, has been leveraging CVE-2026-68820 to gain SYSTEM-level privileges on compromised Windows hosts. The exploit is being used as a delivery mechanism for 'FudModule,' a kernel-mode rootkit designed to maintain persistence and evade detection by security software. The exploitation of this race condition in the kernel-mode driver allows attackers to bypass standard user-mode security controls without requiring user interaction.

Technical Details

CVE-2026-68820 is a use-after-free vulnerability residing in the afd.sys driver, which serves as the backbone for the Windows Sockets API. By executing a specially crafted application on a target system, a locally authenticated attacker can trigger a race condition, leading to memory corruption. Successful exploitation grants the attacker full SYSTEM privileges. Because the vulnerability exists within a kernel-mode driver, it provides the attacker with deep access to the operating system, facilitating the deployment of advanced rootkits like FudModule.

Attribution Assessment

Security researchers have attributed the active exploitation of this zero-day to the Lazarus Group. This actor is known for its high-precision, financially and espionage-motivated campaigns. The use of a kernel-mode rootkit in conjunction with a zero-day exploit aligns with the group's established TTPs (Tactics, Techniques, and Procedures) for maintaining long-term access to high-value targets.

Implications

Organizations running Windows environments are at significant risk if they have not yet applied the August 2026 security updates. The ability for an attacker to escalate privileges to SYSTEM level from a local account significantly lowers the barrier for lateral movement and full domain compromise. Given the active exploitation, this vulnerability should be prioritized for immediate remediation across all enterprise endpoints.

Recommendations

  1. Immediate Patching: Prioritize the deployment of the August 2026 security updates across all Windows servers and workstations.
  2. Endpoint Monitoring: Implement enhanced monitoring for kernel-mode activity and unauthorized driver loading, specifically looking for indicators associated with the FudModule rootkit.
  3. Least Privilege: Enforce strict least-privilege policies to limit the impact of potential local exploitation.
  4. Threat Hunting: Review logs for suspicious local process execution that may indicate an attempt to trigger the afd.sys race condition.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo