CVE detail
CVE-2026-68820
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 22
- within the 30d window
- Peak daily
- 13
- highest bucket
Evidence
Source links by recency
22 source links · newest first
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
newswww.bleepingcomputer.comAug 12, 2026, 3:38 PM- Lazarus Used Post-Quantum Key Exchange to Deliver Zero-DayInfosecurity Magazine
ch reported the vulnerability to Microsoft on July 28 and published its analysis on August 11, the day a patch shipped. CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation. Th
newswww.infosecurity-magazine.comAug 12, 2026, 1:35 PM - Lazarus hackers pair fake job offers with Windows zero-day exploitHelp Net Security
y downloader that profiles the compromised system and retrieves additional components. One of those components exploits CVE-2026-68820, a local privilege escalation vulnerability in the Windows AFD.sys driver. Successful exploitation gives the attackers SYSTEM privileges and lets them deploy FudModule, a Lazarus kernel-mode rootkit built to interfere w
newswww.helpnetsecurity.comAug 12, 2026, 11:48 AM h Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and a
newswww.helpnetsecurity.comAug 12, 2026, 9:34 AMForestTiger , a known Lazarus backdoor. Advertisement. Scroll to continue reading. The afd.sys zero-day, now tracked as CVE-2026-68820, is a use-after-free issue that allows attackers to trigger a race condition and gain System privileges. On August 11, Microsoft fixed the vulnerability as part of its Patch Tuesday updates , and the US cybersecurity ag
newswww.securityweek.comAug 12, 2026, 8:45 AM- Microsoft Fixes 400 Flaws on August Patch TuesdayInfosecurity Magazine
hallenge to process for organizations without automated, risk-based patching programs. The actively exploited zero day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock. A locally authenticated attacker with low privileges could run a specially crafted application and trigger a race condition to gai
newswww.infosecurity-magazine.comAug 12, 2026, 8:12 AM - August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEsCrowdStrike
affected by August 2026 Patch Tuesday Exploited Zero-Day Vulnerability in Windows Ancillary Function Driver for WinSock CVE-2026-68820 is an Important elevation of privilege vulnerability affecting the Windows Ancillary Function Driver for WinSock and has a CVSS score of 7.0 . A use-after-free flaw (CWE-416) allows a low-privileged local attacker to el
vendorwww.crowdstrike.comAug 12, 2026, 8:00 AM Microsoft Patch Tuesday for August 2026 fixes 398 CVEs, including an actively exploited zero-day and a wormable DNS flaw enabling remote code execution. Microsoft released its Patch Tuesday security updates for August 2026 on Tuesday, covering 398 new CVEs across Windows, Office, Azure, Exchange Server, SharePoint, Teams, GitHub Copilot, .NET, and a range of other […]
newssecurityaffairs.comAug 12, 2026, 6:49 AMued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock ( CVE-2026-68820 ), which, according to Todd Schell , principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized at
newswww.csoonline.comAug 12, 2026, 12:45 AMarked as "critical." Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This vulnerability has
vendorblog.talosintelligence.comAug 11, 2026, 10:21 PMation denial-of-service, and arbitrary code execution. Zero-day Vulnerabilities Patched in August Patch Tuesday Edition CVE-2026-72971: Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability This is a link-following flaw that may allow an authenticated attacker to perform local tampering. CVE-2026-62832: Windows User Profile
vendorblog.qualys.comAug 11, 2026, 9:55 PM- 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked oneThe Register Security
(and possibly other miscreants) found and attacked one of these flaws as a zero-day in early June. The bug, tracked as CVE-2026-68820, is a use-after-free in the Windows Ancillary Function Driver for WinSock. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition,” Redmond warned,
newswww.theregister.comAug 11, 2026, 9:31 PM - Microsoft Plugs Nearly 400 Security HolesKrebs on Security
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
newskrebsonsecurity.comAug 11, 2026, 9:28 PM ktop browser security patches so far this month. SharePoint: critical RCE chain by Rapid7 Today sees the publication of CVE-2026-63520 , a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer , and published today in coordination with Microsoft; this vulnerability is the se
vendorwww.rapid7.comAug 11, 2026, 9:10 PMh code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only
newsthehackernews.comAug 11, 2026, 8:10 PMcluding a high-severity vulnerability that has been exploited in the wild as a zero-day. The exploited flaw, tracked as CVE-2026-68820, is described as a use-after-free issue in Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver functioning as the backbone for the Windows Sockets API. Microsoft says threat actors have been exploiti
newswww.securityweek.comAug 11, 2026, 6:46 PMof the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 27.1%. Important CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability CVE-2026-68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and
vendorwww.tenable.comAug 11, 2026, 6:04 PM- The August 2026 Security Update ReviewZero Day Initiative
g actively exploited, at least as 0-days. Again, we’ll start with the bug under active attack and move on from there. - CVE-2026-68820 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability This bug allows attackers to execute code at SYSTEM level. Bugs of this type are often paired with code execution bugs to take over a
vendorwww.thezdi.comAug 11, 2026, 5:56 PM YSTEM** privileges and disable EDR visibility. Following responsible disclosure, Microsoft assigned the vulnerability **CVE-2026-68820** and released a patch on August 11, 2026, as part of their August Patch Tuesday updates. The attackers’ command-and-control infrastructure consists of compromised **Roundcube** and **WordPress** servers hosting **Relay
newsresearch.checkpoint.comAug 11, 2026, 5:30 PMNo excerpt available.
Mitigationwww.cisa.govAug 11, 2026, 5:19 PM- CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityMicrosoft MSRC
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
vendormsrc.microsoft.comAug 11, 2026, 2:00 PM ee new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
governmentwww.cisa.govAug 11, 2026, 12:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-59122CVSS 7.0 · High
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locall…
- CVE-2026-58629CVSS 7.0 · High
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
- CVE-2026-47653CVSS 8.8 · High
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- CVE-2026-45653CVSS 7.0 · High
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-45635CVSS 8.1 · High
Access of resource using incompatible type ('type confusion') in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
- CVE-2026-45603CVSS 7.0 · High
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to eleva…