ThreatCluster

CISA Alerts on Exploitation of Windows Ancillary Function Vulnerability CVE-2026-68820

First seen 14 Aug 2026, 13:29 UTC Cybersecuritynewsnvd.nist.gov 80% similarity 70

Article Content

Browse articles
ThreatCluster

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a Microsoft Windows vulnerability, CVE-2026-68820, which is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock. This vulnerability allows an authorized attacker to elevate privileges locally. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The first public proof of concept (PoC) was released on August 13, 2026. Organizations using affected Windows systems are at risk, and immediate action is recommended to mitigate potential attacks. The vulnerability highlights the ongoing challenges in securing Windows environments against privilege escalation attacks.

Key Points: • CVE-2026-68820 is a use-after-free vulnerability in Windows Ancillary Function Driver. • CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog on August 11, 2026. • The first public proof of concept for CVE-2026-68820 was released on August 13, 2026.

ThreatCluster AI How this analysis works

Timeline

2024-08-13
CVE-2024-38193 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
CVE-2026-68820 added to CISA KEV
CISA included the vulnerability in its Known Exploited Vulnerabilities Catalog due to active exploitation.
Cybersecuritynews
2026-08-13
First public PoC for CVE-2026-68820 released
The first proof of concept demonstrating the exploitation of the vulnerability was made public.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story