Vulnerabilities & Exploits

CISA Orders Two-Week Fix for Exploited Windows Bug

CISA gave federal agencies until August 25 to patch CVE-2026-68820, a Windows Winsock use-after-free bug Microsoft confirmed was being exploited by North Korean actors in a recruiting-focused campaign. It was the only Patch Tuesday flaw Microsoft said was active in real attacks.

The bug sits in Winsock, the Windows networking component that helps browser traffic reach the internet. In plain terms, an attacker first needs a low-privilege foothold, then can abuse the memory bug to turn limited access into higher privileges on the endpoint; a restart is required and there is no workaround, so remediation depends on restart timing as much as on the patch itself.

For federal shops, especially in defense and aerospace, the lure is the hiring pipeline as much as the Windows machine. If applicant-facing workflows or recruiter contact channels are in play, a compromise can start there and then jump into the endpoint with elevated control.

1 source · Aug 12

CVE-2026-68820

NVD KEV

Known exploited · CISA KEV

CVSS 7 HIGH: use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges… Microsoft patch: 5120238.

Patch available KB5120238 Download →

CISA federal remediation date Aug 25

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-08-12

Every edition of this story: CISA Orders Two-Week Fix for Exploited Windows Bug

More from today