Microsoft's August 11 Patch Tuesday shipped 421 fixes. Check Point says Lazarus weaponized CVE 2026 68820, a Windows core networking driver (AFD.sys) privilege escalation bug, to install its FudModule kernel rootkit.
Microsoft's August 2026 Patch Tuesday, released August 11, fixed 421 separate flaws across its software. At least one of them was already being used in the wild before the patches landed. The single bug that matters this month is CVE-2026-68820, a local-privilege-escalation flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys), rated CVSSv3 7.0.
The in-the-wild exploitation is attributed by Check Point Research to Lazarus, a North Korea-linked hacking group. Microsoft has confirmed only that the flaw was exploited as a zero-day; it has not publicly named the actor. Check Point says Lazarus chained CVE-2026-68820 with an earlier intrusion, typically a phishing or "job offer" lure, to elevate from a normal user account to SYSTEM, then install a new variant of FudModule, Lazarus' kernel-mode rootkit.
AFD.sys is a kernel driver reachable only from a session that already has code execution on the box, which makes the zero-day the second-stage weapon rather than the entry point. The patch-priority question is this single local-elevation bug on any Windows host that has been exposed to phishing or malware in the last several months.
Patch totals vary across vendor trackers (421 at The Register and SecurityWeek, 400 at BleepingComputer, 398 at Tenable) because each outlet counts differently; the underlying release is the same. The action is unchanged: prioritize CVE-2026-68820, then work the rest of the queue.