TLP:CLEAR
Microsoft August 2026 Threat & Deployment BriefAn Exploited Kernel Zero-Day, a Wormable DNS RCE, and 398 CVEs

Deploy the Windows August cumulative first: it fixes the AFD.sys zero-day Lazarus is exploiting for SYSTEM, and a wormable DNS remote code execution flaw ships in the same update.

Deploy first
Windows client and server August 2026 security update (KB5121003 / KB5120240 / KB5120249)
Act units
3
Hunt required
1 unit(s) — exploited pre-fix
Release
Microsoft 2026-08-11
CVEs
398–421 (by counter)
KEV read
2026-08-11
Report
ITS-EXV-2026-0811

The Windows cumulative ships first, and it does two jobs at once. It fixes CVE-2026-68820, an AFD.sys kernel-driver flaw already exploited in the wild to gain SYSTEM — Check Point attributes the activity to Lazarus deploying its FudModule rootkit. The same update also fixes a wormable DNS Server flaw (CVE-2026-62878, 9.8) and unauthenticated remote code execution in WDS and QUIC. One deployment closes the exploited escalation and the wormable entry together.

This is a severity inversion, and it is the reason to read past the CVSS column. The flaw being exploited scores 7.0 and is rated Important; the wormable DNS flaw scores 9.8 and Critical but has no exploitation signal. A severity-ordered queue buries the 7.0 you are being attacked through and chases the 9.8 nobody has touched. Both ride the same cumulative, so the argument is moot the moment you deploy it — which is the point.

Patching does not answer whether you were already hit. CVE-2026-68820 was a zero-day: exploited before this fix existed. Deployment closes the door. It tells you nothing about a foothold that already escalated to SYSTEM and dropped a rootkit — and FudModule's whole purpose is to blind the tooling that would tell you. Compromise assessment is a separate obligation on this unit.

Exposed servers still need their own change. SharePoint ships three network remote-code-execution fixes (CVE-2026-65665, -63514, -70321, all 8.8), and Exchange fixes CVE-2026-62911, an authentication-bypass that ZDI says lets an attacker take over every user's mailbox — demonstrated at Pwn2Own Berlin. The Windows update does not touch either. July's brief flagged an embargoed SharePoint RCE due in August; August delivers SharePoint RCE.

The worklist

1

Windows client and server August 2026 security update (KB5121003 / KB5120240 / KB5120249)

Per-product servicing — see table
ACT · under attack
emergency change, ≤72h

Why now. CVE-2026-68820 is KEV-listed with a 25 August federal deadline and Microsoft confirms exploitation in the wild. It is a local elevation of privilege — an attacker needs a foothold first — so on its label it looks like something you could defer. Active exploitation is the reason you cannot: Check Point attributes the activity to Lazarus, using the flaw to reach SYSTEM and load the FudModule rootkit, which then disables the endpoint tooling that would otherwise catch the rest of the intrusion. The urgency here is the evidence, not the reachability. That same Windows update — this month's cumulative for client and server, the rank-1 unit here — is also the only route to a wormable DNS Server remote code execution and to unauthenticated remote code execution in WDS and QUIC. Those are the flaws that give a network attacker the initial foothold this elevation is built to escalate from, so a single Windows update closes both halves at once.

This unit cannot slip. Assessed to cut 1 of the identified chains — see the cut section, where this is labelled as a judgement rather than a finding.

ProductPackageCarries
Windows 11 (24H2 / 25H2)KB5121003CVE-2026-68820, CVE-2026-62832, CVE-2026-72971
Windows 11 (22H2 / 23H2)KB5120240CVE-2026-68820, CVE-2026-62832
Windows 10 22H2 (ESU)KB5120249CVE-2026-68820
Windows Server 2016 / 2019 / 2022 / 2025 monthly cumulative (carries the DNS, WDS, QUIC, DHCP, RRAS and SMB fixes)not establishedresolve via vendor advisory before deployment

Also inside: Two of this month's three zero-days ride this update and neither is exploited: CVE-2026-62832 (User Profile Service elevation of privilege) and CVE-2026-72971 (Container Isolation tampering) were both publicly disclosed before release. Public disclosure escalates a flaw one tier under this model, but the escalator is a no-op here because this update is already Act on the exploited AFD flaw and the wormable DNS RCE — they are passengers, not reasons. The update also carries client-side remote code execution in GDI+ (CVE-2026-62822, 8.8) and the Remote Desktop client (CVE-2026-62824, 8.8); both are Critical-scored and both need a user to open a file or connect to a hostile server, so they too ride along rather than drive the deployment.

Patching is not remediation. CVE-2026-68820 was exploited as a zero-day, before this fix existed, so deployment and compromise assessment are two obligations and this unit discharges only the first. The reported payload makes that gap sharp: FudModule is a rootkit whose job is to disable the very detection you would use to find it, so a clean endpoint console is not evidence of a clean endpoint. Hunt for the escalation predating install — anomalous SYSTEM-level process creation, driver loads consistent with bring-your-own-vulnerable-driver, and gaps or tampering in EDR telemetry rather than clean telemetry. Assume that on any host where this ran, the tooling that would confirm compromise may itself have been blinded.

Then. Deploy the update for your build and reboot. Then treat the exploited flaw as a hunt, not only a patch — see the compromise-assessment note. For the wormable and unauthenticated server flaws, the deployment order argument is over on any Windows host that answers DNS, DHCP, WDS or QUIC from an untrusted segment: those are core services with no separate installer, so the monthly security update is the fix and there is no partial option. Resolve the Windows Server update against the Security Update Guide for your build before scheduling — the server KB is not established in this brief.

The analyst's judgment in this unit

It ships first because it is being exploited right now — KEV-listed, with Check Point tying the activity to Lazarus. The honest caveat: this flaw only helps an attacker who is already on the machine — it raises them to SYSTEM, it does not get them in. So an estate that has already patched every way in this month, and is sure nothing is already inside, gets less from this one fix than its rank suggests. We still put it first for two plain reasons: you do not get to assume nothing is already inside — that is what the compromise-assessment step is for — and the same update also fixes the wormable DNS flaw, which is a way in. Separately: the claim below that this update breaks the most attack chains is the Exvora AI team's analysis, not something Microsoft attests.

2

SharePoint Server August 2026 security update

Per-product servicing — see table
ACT · structural
≤5 days

Why now. SharePoint is a listed exposed technology: a collaboration server reachable from an untrusted network by design, and the product that carried the exploited flaw at the top of last month's brief. This release ships three network remote-code-execution fixes in it. None has an exploitation signal yet, which is why this unit sits behind the Windows cumulative rather than beside it — but the class has been under active attack across 2026, and an internet-facing farm with an unpatched network RCE is a five-day decision, not a normal-cycle one.

ProductPackageCarries
SharePoint Server Subscription Edition / 2019 / 2016not establishedresolve via vendor advisory before deployment

Also inside: July's brief recorded that Rapid7 had disclosed the first half of an unauthenticated SharePoint RCE chain, with the second half embargoed and expected in the August release. August ships SharePoint RCE. Whether any of these three CVEs is that specific embargoed half is not established here, and we are not asserting the chain completion without a source that names it — resolve it against the Security Update Guide and the reporter's follow-up before relying on it either way.

Then. Installing the Windows cumulative does not patch a SharePoint farm. SharePoint servicing is its own path with its own change window, its own validation and a Configuration Wizard run. The KB numbers are not established in this brief — resolve them per SKU against the Security Update Guide, and where a farm is published to the internet, treat this as the five-day structural-Act item it is.

The analyst's judgment in this unit

This unit is Act, not Prioritise, for two reasons: SharePoint is an internet-facing server, and a network code-execution flaw clears the impact gate. But none of these three CVEs is being exploited yet. So if your SharePoint is not reachable from an untrusted network, it drops to Prioritise and a 14-day clock. If you run no on-premises SharePoint, this unit does not apply to you.

3

Exchange Server August 2026 security update

Per-product servicing — see table
ACT · structural
≤5 days

Why now. Exchange is the mail edge — exposed technology in the frozen list. CVE-2026-62911 is an authentication bypass that ZDI describes as letting an attacker take over the mailboxes of all Exchange users, and it was demonstrated at Pwn2Own Berlin, which means a working exploit is in a researcher's hands even though it is not yet public. Microsoft scores it 8.0. It has no in-the-wild exploitation signal today, so it is a structural five-day item, not an emergency — but a mailbox-takeover on an internet-facing server is not something to leave on the normal cycle.

ProductPackageCarries
Exchange Server Subscription Edition (2016 / 2019 receive updates only under Extended Security Updates)not establishedresolve via vendor advisory before deployment

Then. Exchange servicing is its own path, separate from the Windows cumulative. The KB is not established here — resolve it against the Security Update Guide for your build. Exchange 2016 and 2019 are out of support and receive this update only under Extended Security Updates; if you run either without ESU, this unit has no deployable artifact for you and the mitigation lane is the only lane you have.

The analyst's judgment in this unit

We rank this third, below SharePoint, because SharePoint carries three network code-execution flaws to Exchange's one authentication bypass, and SharePoint has been attacked more often in 2026. If your Exchange is more exposed than your SharePoint — or you run no SharePoint on-premises — swap ranks 2 and 3. Nothing above them changes.

The cut — why the top unit cannot slip

Confidence: moderate — analytic judgement, not vendor-attested

The Windows client and server August 2026 security update (KB5121003 / KB5120240 / KB5120249) is the cut: it removes CVE-2026-68820, the actively-exploited AFD.sys escalation link, which an intrusion pairs with any unauthenticated entry this month to turn a foothold into SYSTEM and a rootkit. It cannot slip.

Basis. Stage 2 composition pass. The exploited flaw is an escalation link (local, to SYSTEM); this month's entry links (SharePoint RCE, Exchange auth-bypass, DNS/WDS/QUIC unauthenticated RCE) all land on Windows hosts where AFD escalation co-locates. Check Point's report of Lazarus using it to load FudModule is the vendor-attested sighting that makes this the live escalation rather than a theoretical one. No advisory attests the chain; it is inferred from architecture and the reported tradecraft.

What would lower this. On a well-tiered estate where user-level footholds cannot reach the hosts running exposed entry services, the escalation and entry links do not co-locate and the cut's leverage drops. An estate already patched against this month's unauthenticated entries, with no pre-existing footholds, gains only the escalation fix — still worth deploying, but the chain it cuts is hypothetical for them. And an attacker who already reached SYSTEM before the patch keeps what they took; the cut is prevention, not remediation.

Confidence: moderate-high — analytic judgement, not vendor-attested

The severity inversion this month is structural, not incidental: the one flaw being exploited scores 7.0 and is rated Important, while the highest-scored flaws in the release — the 9.8 DNS, WDS and QUIC RCEs — have no exploitation signal.

Basis. Direct comparison of vendor-attested exploitation status (KEV listing for CVE-2026-68820) against the vendor's and ZDI's own scores. The scores and the KEV listing are facts; the claim that this recurs rather than being a one-off is the judgement, resting on the same pattern across the model's 2026 corpus, where six of seven cycles saw the exploited flaw out-scored by an unexploited one.

What would lower this. One month is one data point and the corpus is thin and selected on interesting months. If the wormable DNS RCE is exploited within weeks, the inversion collapses for August specifically — the 9.8 would then be both highest-scored and exploited — though the deployment answer (ship the cumulative) does not change.

Confidence: moderate — analytic judgement, not vendor-attested

SharePoint and Exchange reach Act structurally, on exposure plus a gate-passing impact, with no exploitation evidence behind this month's specific CVEs. That is the one set of calls in this brief the evidence does not back.

Basis. Both are frozen-list exposed technologies; SharePoint's CVE-2026-65665 is network RCE and Exchange's CVE-2026-62911 is network authentication-bypass, so both clear the impact gate. The structural verdict is designed to fire before exploitation evidence exists — that is its purpose — but it is a forecast about reachability, not an attested fact about attacks.

What would lower this. A farm or mail server behind an authenticating reverse proxy is a different exposure than one on the public internet, and the tree cannot tell them apart. Where the exposed surface is not actually reachable from an untrusted network, both units drop to Prioritise and the 5-day clock becomes 14.

Method, sources, caveats

Sources

SourceAdmiraltyUsed for
https://msrc.microsoft.com/update-guide/releaseNote/2026-AugA1Vendor release note; primary for every Microsoft CVE in this brief
https://www.cisa.gov/known-exploited-vulnerabilities-catalogA1KEV read live 2026-08-11 (catalog 2026.08.11): CVE-2026-68820 added 2026-08-11, dueDate 2026-08-25, knownRansomwareCampaignUse Unknown. Confirms CVE-2026-72971 and CVE-2026-62832 are NOT KEV-listed
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820A1Vendor advisory for the exploited AFD.sys zero-day: locally authenticated attacker, race condition, SYSTEM privileges; Exploit Code Maturity Unproven
https://www.zerodayinitiative.com/blog/2026/8/11/the-august-2026-security-updaB2Counts (398 / 62 Critical); zero-day detail and CVSS; DNS 9.8 wormable, WDS and QUIC 9.8, DHCP/RRAS/SMB/GDI+/RDP-client scores; SharePoint 8.8 RCE trio; Exchange CVE-2026-62911 mailbox-takeover and Pwn2Own
https://www.tenable.com/blog/microsofts-august-2026-patch-tuesday-addresses-39B2Counts (398 / 42 Critical, 1 Moderate); EoP 40.7% / RCE 27.1% breakdown; CVE-2026-68820 detail and the two additional afd.sys EoP CVEs; WDS TFTP 9.8 unauthenticated; SharePoint RCE trio
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuB2Counts (400 / 42 Critical) and type breakdown; Microsoft's exploitation wording for CVE-2026-68820; Check Point / Lazarus / FudModule attribution; Windows 11 KB5121003 and KB5120240 and Windows 10 KB5120249 package numbers; publicly-disclosed wording for the two other zero-days
https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cveB2Alternate release count (421 CVEs, one exploited zero-day) by a different counting methodology; corroboration of the single exploited zero-day