Skip to content
Rush Commerce
Field Notes3 min read

Windows AFD zero-day CVE-2026-68820: patch by Aug 25

August Patch Tuesday shipped a fix for an actively exploited Windows WinSock driver flaw. CISA's deadline is August 25. Here's what to patch first.

Today's Patch Tuesday is large enough that the important item will get lost in it. One flaw in the pile is already being used against real machines: CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock — afd.sys. It turns any low-privilege foothold into SYSTEM. CISA added it to the Known Exploited Vulnerabilities catalog the same day the patch landed, with a federal remediation deadline of August 25, 2026.

What actually happened

Tenable counts 398 CVEs in this cycle — 42 critical, 355 important, one moderate — excluding two MITRE-assigned IDs. SecurityWeek's tally is 421. The gap is counting methodology, not disagreement, and the number that matters here is one.

CVE-2026-68820 carries a CVSS 3.1 score of 7.0 with a local attack vector: an authenticated low-privilege user runs a crafted application, wins a race condition, and gets SYSTEM. It affects Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2012 through 2025 — twenty product families. Microsoft confirms exploitation in the wild. Tenable's Satnam Narang notes this is the fourth exploited afd.sys zero-day since 2022, and that one of the earlier three was reportedly used by North Korea-linked operators. Nobody has publicly pinned this one to an actor yet, so treat attribution as open. Two sibling AFD bugs, CVE-2026-61348 and CVE-2026-70307, were patched with no evidence of exploitation.

CISA added two more exploited CVEs today. CVE-2026-20349 is a CVSS 8.6 flaw in the Remote Access SSL VPN service on Cisco Secure Firewall ASA (9.16.1–9.20.4.46) and FTD (7.0.0–10.0.2): a crafted HTTP request reloads the device, unauthenticated, from the internet. The third was the Metabase SQL injection we covered last week.

Why it matters for your business

A local privilege-escalation bug reads like a low priority because it needs a foothold first. That reasoning is backwards. Every phishing click, every stale VPN credential, every compromised contractor laptop is the foothold — a low-privilege one. AFD-class bugs are what converts that into full control of the box, and the reason they keep getting exploited is that they're the reliable second step in a chain that starts with something mundane.

So the sequence for this week is: patch the perimeter box first, then the endpoints. If you run a Cisco ASA or FTD as your VPN concentrator, that's an unauthenticated remote hit on a device that is by definition internet-facing — it goes tonight. The Windows updates go next, and "we have automatic updates on" is not the same as verifying build numbers on the servers that matter. Domain controllers, file servers, the box running your line-of-business app. Check those by hand.

The larger point: three exploited CVEs landed on one Tuesday across a firewall, an OS driver, and a BI tool. If your patching process is one person remembering, the process is the vulnerability.

Key takeaways

  • CVE-2026-68820 is an actively exploited use-after-free in Windows afd.sys, CVSS 7.0, granting SYSTEM from a low-privilege foothold
  • CISA added it to the KEV catalog on August 11 with a federal remediation deadline of August 25, 2026
  • CVE-2026-20349 hits Cisco ASA/FTD Remote Access SSL VPN — unauthenticated remote reload, CVSS 8.6, also added to KEV today
  • Patch the internet-facing firewall first, then verify Windows build numbers by hand on servers rather than trusting auto-update

Patching shouldn't depend on someone remembering. We inventory what you actually run, put updates on a schedule with verification, and tell you which boxes get patched tonight versus this month. See how we harden small-business infrastructure or book an audit.

Sources: Tenable, SecurityWeek, MSRC — CVE-2026-68820, CISA KEV catalog.

  • #cve-2026-68820
  • #patch-tuesday
  • #cisa-kev
  • #windows
  • #patch-management
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.