Multiple vulnerabilities in Microsoft Windows (August 12, 2026)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Multiple vulnerabilities have been discovered in Microsoft Windows. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation and remote denial of service. Microsoft indicates that the vulnerability CVE-2026-68820...
CSIRTS triage
- What
- Multiple vulnerabilities enable remote arbitrary code execution, privilege escalation, and denial of service.
- Who is affected
- Microsoft Windows systems running vulnerable versions.
- Urgency
- Critical; active exploitation is occurring.
- Action
- Install the latest Microsoft security updates immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows
Get an email when a new Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1001/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-68820Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-68820 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedMicrosoft Monthly Security Update (August 2026)hkcert
- unknownexploitedSecurity Alert: Microsoft Releases August 2026 Security Updatesjpcert
- unknownexploitedNCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windowsncsc-nl
- highexploitedCVE-2026-68820: Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker …nvd
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- highexploitedCVE-2026-68820: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerabilitymsrc
- criticalexploitedCVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerabilitycisa-kev
Recent advisories for Microsoft Windows
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0353 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Windowsncsc-nl · 2026-09-08
- highCVE-2026-81353: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
- highCVE-2026-81352: Heap-based buffer overflow in Microsoft Windows Codecs Library allows an unauthorized attacker…nvd · 2026-09-08
- mediumCVE-2026-78453: Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an u…nvd · 2026-09-08
- mediumCVE-2026-78452: Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker…nvd · 2026-09-08
- mediumCVE-2026-78451: Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthoriz…nvd · 2026-09-08
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Typo3 (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans les produits SAP (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans Mattermost Server (08 septembre 2026)2026-09-08
- unknownVulnérabilité dans les produits Adobe (08 septembre 2026)2026-09-08
- unknownMultiples vulnérabilités dans strongSwan (08 septembre 2026)2026-09-08