Particle.news

Microsoft Patches 398 Flaws as Active Winsock Exploit Is Reported

Applying the updates is urgent because a local Winsock bug is being used to elevate attackers to SYSTEM privileges.

Overview

  • Microsoft released security updates on Aug. 11 that fix 398 distinct vulnerabilities across Windows, Office and multiple cloud and server products.
  • At least one Windows flaw, CVE-2026-68820 in the Ancillary Function Driver for WinSock, is being actively exploited to gain SYSTEM privileges so administrators should prioritize that patch.
  • The August update set includes 42 vulnerabilities Microsoft labels critical and more than 200 Windows bugs plus 128 Office fixes, several of which are remote code execution flaws that can let attackers run code on target machines.
  • A proof-of-concept called ShieldBreak claims to bypass a recent Defender fix for the RoguePlanet issue (CVE-2026-50656) but that claim remains unverified by other researchers and Microsoft has not confirmed it.
  • Microsoft says some Azure vulnerabilities were repaired server-side so no action is needed for them, but it still urges admins to enable Windows Update and apply the remaining patches immediately to limit further compromise.