Microsoft has released its August 2026 Patch Tuesday security updates, patching around 400 vulnerabilities across Windows and other products. The updates include fixes for one actively exploited zero-day and two vulnerabilities that had already been publicly disclosed.
The actively exploited flaw is CVE-2026-68820, a Windows Ancillary Function Driver for WinSock use-after-free vulnerability. Microsoft says the flaw can allow attackers to gain SYSTEM privileges.
Security researchers at Check Point said the North Korean Lazarus group exploited CVE-2026-68820 in the Operation DreamJob campaign to deploy the FudModule kernel-mode rootkit. The threat actor has also used the CVE-2025-49113 RCE flaw to exploit vulnerable Roundcube webmail servers. The compromised servers were infected with the RelayShell PHP webshell that turns compromised web servers into relay nodes within the attacker’s command-and-control infrastructure.
Microsoft also fixed two publicly disclosed flaws - CVE-2026-62832, a Windows User Profile Service elevation-of-privilege vulnerability, and CVE-2026-72971, a Windows Container Isolation FS Filter Driver tampering vulnerability.
The August updates also address security issues in Microsoft Exchange Server, Microsoft Teams, and other products.
Separately, Cisco has warned that attackers are actively exploiting CVE-2026-20349, a high-severity denial-of-service vulnerability in Secure Firewall ASA and Secure Firewall Threat Defense (FTD).
The vulnerability can be used to remotely crash affected firewalls when certain remote access services are enabled, including SSL VPN, IKEv2 Remote Access VPN, and Zero Trust Network Access on FTD devices.
Cisco has released hot fixes for affected ASA and FTD versions and says there are no workarounds. Customers are advised to upgrade to a fixed release as soon as possible. Cisco says it became aware of active exploitation in August but has not disclosed who is behind the attacks or which organizations have been targeted.