Published on August 24, 2026 · The mitza.es team

On August 11, 2026, Microsoft released its monthly security bulletin, fixing 421 vulnerabilities in total, 62 of them marked as critical. It's one of the heaviest bulletins of the year, and among all those fixes there's one that deserves absolute priority: a zero-day that was already being actively exploited even before a patch existed.
The zero-day you need to patch right now
It's CVE-2026-68820, a privilege escalation vulnerability in Windows' Ancillary Function Driver for WinSock. It lets an attacker who already has local access to a machine escalate to SYSTEM privileges — that is, full control over the machine. Microsoft confirms it has already been exploited in the wild as a zero-day, and the vulnerability appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, the US cybersecurity agency that tracks flaws with confirmed active exploitation.
Other critical vulnerabilities in this bulletin
- CVE-2026-62893: remote code execution in Windows Deployment Services TFTP Server, with a CVSS score of 9.8 out of 10.
- CVE-2026-65791: remote code execution in Windows iSCSI Target Service, also scoring CVSS 9.8, caused by a buffer overflow that an unauthenticated remote attacker can exploit with relative ease.
Why active exploitation trumps the technical score
It's common to assume you should prioritize the flaws with the highest CVSS score, but that's not always the right strategy. The WinSock zero-day has a lower technical severity score than other vulnerabilities in this same bulletin, but because it's being actively exploited right now, it's the one that represents the real, immediate risk. A flaw scored 9.8 but with no confirmed exploitation yet is, in practice, less urgent than a more modest one that's already being used against real systems.
What to do if you manage Windows machines in your business
Update as soon as possible, prioritizing the active zero-day. If you have several machines in your company, it's a good time to check once and for all which ones are up to date and which aren't, instead of waiting for an incident to expose it. It's the same logic we already explained with the critical macOS vulnerability from this same month: it doesn't matter which operating system you use, keeping things up to date remains the most effective — and cheapest — defense there is. Our IT maintenance service includes this review, and if you want a more complete diagnosis of your overall exposure, you can request a tailored audit.