Microsoft patches Windows kernel zero-day exploited by Lazarus
Microsoft $MSFT patched CVE-2026-68820 this week, a Windows kernel flaw already under active exploitation. North Korea's Lazarus group used it to gain SYSTEM privileges and deploy the FudModule rootkit, per SecurityWeek. It is the fourth afd.sys zero-day exploited in the wild sin
Microsoft $MSFT patched CVE-2026-68820 as part of its August 2026 Patch Tuesday release, fixing 421 vulnerabilities in total. The flaw, a use-after-free bug in afd.sys, the kernel-mode driver that underpins the Windows Sockets API, was already being actively exploited before the patch shipped. According to SecurityWeek and BleepingComputer, North Korea's Lazarus Group used CVE-2026-68820 to trigger a race condition and elevate privileges to SYSTEM level without requiring any user interaction, then deployed its FudModule kernel-mode rootkit on compromised machines. The Register reported that the exploitation was detected before Microsoft's fix became available. This marks the fourth afd.sys zero-day exploited in the wild since 2022, following CVE-2025-32709, CVE-2025-21418 and CVE-2024-38193, the last of which was also attributed to Lazarus-linked operators. The recurrence of the same Windows subsystem across four separate campaigns in four years points to a specific, sustained targeting pattern by state-linked actors rather than a one-off discovery, and underscores why afd.sys remains a priority target for both attackers and Microsoft's own security teams. Anyone running Windows systems that have not yet applied this month's cumulative update remains exposed to an exploit chain that grants full SYSTEM-level control with no user interaction required.