Skip to content

CVE-2026-65789

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
August 13, 2026
Last Seen
September 9, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This vulnerability was actively exploited for weeks before a patch was released on August 1...

On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These vulnerabilities allow local attackers to escalate privileges to SYSTEM level, posing sig...

Public Exploits

Checking GitHub for proof-of-concept code…