Skip to content

CVE-2026-68820

CVE

Threat entity extracted from intelligence sources

Frequency
14
occurrences
First Seen
August 12, 2026
Last Seen
September 26, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This vulnerability was actively exploited for weeks before a patch was released on August 1...

The Russian threat group Sandworm has been targeting IT professionals through a social engineering campaign since May 2026. The campaign, attributed to the UAC-0145 subgroup, involves impersonating IT companies and recruiters to lure victims into downloading a trojanized WireGuard VPN client. Victim...

In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that could steal GitHub tokens. The updates are crucial for protecting a wide range of Mi...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of a Microsoft Windows vulnerability, CVE-2026-68820, which is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock. This vulnerability allows an authorized attacker to elevate pr...

Public Exploits

Checking GitHub for proof-of-concept code…