Vulnerability
Published 2026-08-11
Verified 2026-09-19

Windows WinSock AFD elevation of privilege (CVE-2026-68820), exploited

Microsoft's 11 August 2026 security update for CVE-2026-68820 fixes a use-after-free in the Windows Ancillary Function Driver for WinSock. A locally authenticated attacker who wins a race with a crafted application can elevate to SYSTEM. Microsoft rates it Important, CVSS 3.1 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H), and marks Exploitation Detected. CISA added it to the Known Exploited Vulnerabilities catalog on 11 August 2026 with the same-day Cisco ASA/FTD and Metabase KEV batch. Apply the August 2026 cumulative update for your Windows build and reboot so the kernel driver replacement takes effect. Distinct from SharePoint CVE-2026-55040 already on this desk.

Product
Windows Ancillary Function Driver for WinSock (Windows client and Server)
Versions
Supported Windows 10/11 and Windows Server builds before the August 2026 cumulative update (see MSRC)
CVSS
(CVSS 3.1, Microsoft)
Exploited in Australia?
unknown
Patch to
August 2026 cumulative update for your build (MSRC CVE-2026-68820); reboot required

Primary: Microsoft MSRC (CVE-2026-68820) · Vendor: Microsoft Security Update Guide · CVE: CVE-2026-68820, CVE-2026-55040 · CISA KEV addition notice (11 Aug 2026)

vulnerabilities identity