Patch Tuesday hits 421 fixes as Lazarus exploits a new zero-day

TL;DR Summary
Microsoft’s August Patch Tuesday patches 421 CVEs, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock that North Korea’s Lazarus Group allegedly weaponized as a zero-day in June. Analysts link the campaigns to the Dream Job operation, which uses fake defense-industry job sites and a Trojanized PDF viewer called SecurityPDF delivered via phishing to install the backdoor Troy. Other notable fixes include CVE-2026-62832 (privilege escalation via loading another user’s registry hive) and CVE-2026-62893 (Windows Deployment Services TFTP remote code execution), among others highlighted by researchers and ZDI.
- 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one The Register
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack The Hacker News
- Microsoft Plugs Nearly 400 Security Holes Krebs on Security
- Microsoft's Patch Tuesday Deluge Continues With August Updates Dark Reading
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day SecurityWeek
Reading Insights
Total Reads
0
Unique Readers
23
Time Saved
5 min
vs 6 min read
Condensed
91%
1,019 → 90 words
Want the full story? Read the original article
Read on The Register