Tag

Afdsys

All articles tagged with #afdsys

Active Windows zero-day drives urgent August patch Tuesday across core services
security1 hour ago

Active Windows zero-day drives urgent August patch Tuesday across core services

Microsoft’s August Patch Tuesday closes 398 CVEs, including CVE-2026-68820—a use‑after‑free in afd.sys that can escalate from code execution to SYSTEM and is under active exploitation—making it the top priority; four other high‑severity flaws (CVE-2026-62878 in Windows DNS Server, CVE-2026-62893 in Windows Deployment Services, CVE-2026-62815 in Microsoft QUIC, and CVE-2026-59124 in HPC Pack) are unauthenticated RCEs whose exploitation depends on service exposure. The update also finishes a two‑part SharePoint chain (CVE-2026-55040 and CVE-2026-63520) first disclosed by Rapid7. Prioritize systems with exposed DNS/WDS/QUIC/HPC services and ensure on‑prem SharePoint farms apply both July and August fixes to close the chain.

security2 hours ago

Microsoft Patch Tuesday Deluge: 398 Flaws Fixed, Zero-Day in afd.sys Exposed

Microsoft released a massive Patch Tuesday, fixing 398 vulnerabilities across Windows and related software, including a zero-day in afd.sys (CVE-2026-68820) and two other publicly disclosed flaws; 42 fixes are critical. AI aided vulnerability discovery, but patching remains heavily human-driven and requires testing. Users should back up data and deploy updates cautiously, as large update bundles may take time to stabilize.