CVE-2026-68820 is a use-after-free in afd.sys, the Windows kernel driver behind the Sockets API. A local attacker wins a race condition and walks away with SYSTEM. Check Point ties it to Lazarus, and CISA added it to the KEV catalog on August 11.

Read the full story: A Windows Socket Driver Bug Handed Lazarus SYSTEM Access →

Transcript

Microsoft just shipped one of its heaviest patch bundles ever, around four hundred flaws. The one that matters scores a seven point zero. It is called CVE twenty twenty six, six eight eight two zero, a use after free in afd dot sys. That is the kernel driver sitting under the Windows Sockets API. Here is why it is dangerous. Every Windows machine loads it, and any process that opens a socket can reach it, no special privileges required. An attacker runs a crafted program, wins a race condition inside the driver, and walks away with SYSTEM. Check Point ties it to Lazarus, inside Operation Dream Job. CISA added it to the exploited catalogue on August eleventh. And this is the fourth afd dot sys zero day caught in the wild since twenty twenty two. Patch this one first.