Overview
- Microsoft released fixes covering 421 CVEs that include CVE-2026-68820, a use‑after‑free in the Ancillary Function Driver for WinSock (afd.sys) that Microsoft says has been exploited to elevate to SYSTEM without user interaction.
- The afd.sys bug is triggered by a locally authenticated race condition where a specially crafted app can run on an affected machine and gain full system privileges.
- Microsoft also flagged CVE-2026-62832 in the User Profile Service as publicly disclosed and likely to be exploited while marking CVE-2026-72971 in unionfs.sys as publicly disclosed but unlikely to see attacks.
- The August release lists product counts that include 236 Windows fixes and 98 Office fixes and also patches two TPM 2.0 reference implementation flaws (CVE-2026-6726 and CVE-2026-6727).
- Security firms warned that historical targeting of afd.sys suggests possible nation‑state tradecraft and urged defenders to apply these updates immediately, monitor for local privilege escalation, and prioritize other noted RCEs and an Exchange elevation bug.