SYS::ONLINE
Wasteland.
Briefs1888
Issues23
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-68820 2026-08-11

CVE-2026-68820: Windows AFD.sys Use-After-Free Added to CISA KEV

"CISA added CVE-2026-68820, a use-after-free privilege-escalation flaw in the Windows Ancillary Function Driver for WinSock, to the Known Exploited Vulnerabilities catalog on 2026-08-11."

CISA added CVE-2026-68820, a use-after-free privilege-escalation flaw in the Windows Ancillary Function Driver for WinSock, to the Known Exploited Vulnerabilities catalog on 2026-08-11.

What Is It

CVE-2026-68820 is a use-after-free (CWE-416) in the Windows Ancillary Function Driver for WinSock. Per Microsoft's description, the flaw "allows an authorized attacker to elevate privileges locally." It carries a CVSS 3.1 base score of 7.0 (HIGH), vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H, local attack vector, high attack complexity, low privileges required, no user interaction, with high impact to confidentiality, integrity, and availability.

Why It Matters

CISA's inclusion of this CVE in the KEV catalog on 2026-08-11 confirms it is being actively exploited. Known ransomware campaign use is listed as Unknown. No public reporting details how the flaw is being used in the observed activity. That said, the requirement for only low existing privileges and no user interaction fits the profile of a second-stage component, the kind of local escalation an intruder who already has a foothold would plausibly chain toward SYSTEM, so defenders should treat it as a post-compromise escalation risk pending further detail. The driver ships on effectively every supported Windows client and server build, so the exposed footprint is wide.

What's Vulnerable

Microsoft lists a broad affected range, patched at these build numbers:

32-bit, x64, and ARM64 platforms are affected depending on the release.

Patch Status

Fixed builds are published by Microsoft; the NVD record was published 2026-08-11 and remains in "Undergoing Analysis." CISA's required action: apply mitigations per vendor instructions in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements," follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure. Due date: 2026-08-25.

Sources