Skip to content

Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly

Share
Source: Badtech.org

Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the difference attributed to counting method or update scope.

The most urgent issue in the supplied coverage is CVE-2026-68820, a use-after-free elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), a core Windows networking driver. The flaw can let a locally authenticated attacker win a race condition and gain SYSTEM privileges, and it was reported as actively exploited in the wild.

TechGig, Mallory.ai, and CyberHub coverage also identified two publicly disclosed Windows flaws in the release: CVE-2026-62832 in the Windows User Profile Service and CVE-2026-72971 in the Windows Container Isolation FS Filter Driver. Separate reporting also highlighted remote-code-execution fixes affecting Windows DNS Server, Windows Deployment Services TFTP Server, Microsoft QUIC, and HPC Pack where those services are deployed.

Sources

Read more

Water utility cyber incidents across at least seven U.S. states disrupted monitoring and control across at least seven U.S. states

CBS News, NBC News, and CNN Newsource via KEYT reported that the FBI and EPA said water and wastewater utilities in at least seven U.S. states experienced malicious cyber incidents, with some activity degrading operations. The reporting says the activity targeted internet-facing programmable logic controllers, or PLCs, which

By Adam Field Source: Badtech.org