Menu

Windows zero-day under attack: why Microsoft's August patches cannot wait

Comingwave team · 6 minute read · published

An IT technician restarts a row of office desktop computers in the early evening after installing updates.

Microsoft released its August 2026 security updates on 11 August, and one of the fixes closes a Windows zero-day, a flaw that attackers were using before a patch existed. The vulnerability, tracked as CVE-2026-68820, lets someone who already has a foothold on a Windows computer take complete control of it. Microsoft lists Windows 10, Windows 11 and Windows Server as affected, so the job for a small or medium business this week is easy to describe: get the August updates onto every Windows PC and server, restart them, and confirm the updates really installed.

What Microsoft released on 11 August

Microsoft's monthly security release is widely known as Patch Tuesday. The August 2026 security updates from the Microsoft Security Response Center cover Windows and a long list of other Microsoft products. BleepingComputer's count of the release puts it at about 400 fixes, 42 of them rated critical, and that figure leaves out issues Microsoft fixed in other products earlier in the month. Counts differ between publications because each one decides what to include, so read the number as a sense of scale and nothing more.

Three entries stand out because Microsoft's own advisories flag them as exploited or publicly known on the day of release.

CVEWindows componentType of flawMicrosoft's status at release
CVE-2026-68820Ancillary Function Driver for WinSockElevation of privilegeExploitation detected
CVE-2026-62832User Profile ServiceElevation of privilegePublicly disclosed, exploitation more likely
CVE-2026-72971Container Isolation FS Filter DriverTamperingPublicly disclosed, exploitation unlikely

The zero-day: CVE-2026-68820

According to Microsoft's advisory for CVE-2026-68820, the flaw is a memory-handling error (a "use after free") in the Ancillary Function Driver for WinSock, a core part of Windows networking. A person who is already logged on to the computer can run a specially crafted program, win a timing race inside the driver, and come out with SYSTEM privileges, the highest level of access on a Windows machine. No action by the user is needed.

Microsoft rates the flaw "Important" with a CVSS base score of 7.0, marks it as "Exploitation Detected", and credits two researchers from Check Point with reporting it. The advisory does not describe who was attacked or how, and we are not going to guess.

Why an "Important" rating still deserves urgency

The rating is lower than "Critical" because the attacker needs to be on the machine first. In practice that first step is the easy part: a staff member opens a fake invoice attachment, a password is reused from a breached website, or a remote access tool is left exposed. At that point the intruder usually has the limited rights of an ordinary staff account. An elevation of privilege flaw is what turns that limited access into full control of the computer, which is the position an intruder wants before switching off security software, collecting other passwords or moving on to the file server.

Picture an accounting practice where the front desk PC runs under a standard account with no administrator rights. That restriction is a sound control, and this flaw is a way around it. Patching puts the control back.

Who is at risk

Microsoft's affected product list for the zero-day is long:

  • Windows 11: versions 23H2, 24H2, 25H2 and 26H1.
  • Windows 10: including version 22H2, the final release.
  • Windows Server: 2012, 2012 R2, 2016, 2019, 2022 and 2025.

Windows 10 needs a closer look. Microsoft ended support for Windows 10 on 14 October 2025, and Microsoft's Extended Security Updates page explains that only PCs enrolled in the paid ESU program keep receiving security fixes. Devices must be on version 22H2 to be eligible, and commercial organisations can stay enrolled for a maximum of three years after the end of support. A Windows 10 PC that is not enrolled will not receive the fix for CVE-2026-68820 at all.

The businesses with the most to lose are those where many people share machines or log on to the same server: remote desktop servers, shared workstations in a warehouse or clinic, and any office where a single compromised account can reach a server holding everyone's files.

What a small business should do this week

The Australian Cyber Security Centre's patching guidance recommends patching workstation operating systems within one month, and internet-facing servers within two weeks, or within 48 hours where the vendor rates the issue critical or a working exploit exists. For higher-threat environments it applies the same 48-hour clock to workstations once a working exploit exists. A working exploit exists here, so treat the August updates as a fast-lane job.

StepWhat to doYou are finished when
1. ListWrite down every Windows PC, laptop and server, including laptops used from home and the old machine in the back office.Each device has an owner and a Windows version next to it.
2. InstallRun Windows Update, or approve the August updates in whatever tool your IT provider uses to manage devices.Every device shows the August 2026 update as installed.
3. RestartReboot each machine. An update that is waiting on a restart is not protecting anything.No device reports a pending restart.
4. VerifyCheck update history or ask for a patch report. The ACSC warns that organisations often believe patches were applied when they failed or were still waiting on a reboot.You have seen evidence, not an assumption.
5. Windows 10Confirm each Windows 10 PC is enrolled in ESU, or isolate it and plan its replacement.No unenrolled Windows 10 device is in daily use.
6. ServersBook a maintenance window for servers, starting with any that are reachable from the internet.Servers are patched and restarted.
7. Admin rightsReview who has administrator rights and remove those that are not needed.Day-to-day work happens under standard accounts.

If nobody in the business owns this list, that is the real gap. Patching is one of the Essential Eight strategies the ACSC recommends, and it only works when someone is responsible for checking it every month. Comingwave is a technology company that provides managed IT support and cyber security services to small and medium businesses, including monitoring and updates. If you still rely on Windows 10 machines, our IT consulting service can help you plan the move to supported systems. To talk it through, request a free first consultation or a written quote.

Key takeaways

  • Microsoft's 11 August 2026 updates fix CVE-2026-68820, a Windows flaw that Microsoft says has already been exploited.
  • The flaw gives an attacker who is already on a machine SYSTEM privileges, so it turns a small break-in into a serious one.
  • Windows 10, Windows 11 and Windows Server 2012 to 2025 are on the affected list.
  • Windows 10 PCs only receive the fix if they are enrolled in Extended Security Updates.
  • Install, restart and verify. ACSC guidance sets a 48-hour clock for the most exposed systems when a working exploit exists.

Frequently asked questions

What is CVE-2026-68820?

It is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock. Microsoft's advisory says a locally authenticated attacker can run a crafted program and gain SYSTEM privileges, and that exploitation has been detected.

Are we protected if Windows Update is set to automatic?

Only once the update has downloaded, installed and the computer has restarted. Laptops that are rarely switched on, machines that are never rebooted and servers on a manual schedule are the usual gaps, so check update history on each device.

Do Windows 10 computers get this fix?

Only if they run version 22H2 and are enrolled in Microsoft's Extended Security Updates program. Microsoft ended standard support for Windows 10 on 14 October 2025, and unenrolled PCs no longer receive security updates.

How quickly should a small business install the August updates?

ACSC guidance allows up to one month for workstations and two weeks for internet-facing servers, and shortens that to 48 hours for the most exposed systems when a working exploit exists. Because this flaw is already being exploited, aim to finish within days.

What does "exploitation detected" mean in a Microsoft advisory?

It is Microsoft's label for a vulnerability it has evidence of attackers using. It does not say how many organisations were affected or who was behind it, and Microsoft's advisory for this flaw gives no further detail.

Need help with your business technology?

Tell us what you need. We reply within one business day.

Get a free quote