// Microsoft 365CRITICAL
Microsoft patched CVE-2026-68820, a critical use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), on August 22, 2026 as part of Patch Tuesday. The flaw enables local privilege escalation to SYSTEM level and was actively exploited in the wild by the Lazarus Group before the patch shipped. The vulnerability poses significant risk to Windows-based Microsoft 365 infrastructure and endpoint security.
// Get alerts for Microsoft 365