
Microsoft has released the August 2026 cumulative update for Windows 11, fixing 236 Windows vulnerabilities, including a privilege-escalation flaw that is already being exploited in attacks.
The KB5121003 update was released earlier today for Windows 11 versions 24H2, 25H2, and 26H1, bringing systems to builds 26100.9168 and 26200.9168. It is part of Microsoft's broader August Patch Tuesday release, which addresses 421 CVEs across Windows, Office, Exchange Server, SharePoint, Azure, Defender, and developer tools.
The most urgent flaw fixed this month is CVE-2026-68820, an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock.
Microsoft says the bug is caused by a use-after-free condition and is being actively exploited in the wild.
The vulnerability was reported by Check Point researchers Moshe Marelus and David Driker and carries a CVSS score of 7.0.
To exploit it, a locally authenticated attacker with low privileges must run a specially crafted application and successfully trigger a race condition. If successful, the attacker can gain SYSTEM privileges without requiring user interaction.
Although the flaw cannot be exploited remotely on its own, vulnerabilities of this type are commonly used after an attacker has already gained an initial foothold on a Windows system.
CheckPoint has published a detailed report about CVE-2026-68820, mentioning that it has been exploited by the North Korean threat group ‘Lazarus' since at least early July 2026, in campaigns targeting military organizations.
Microsoft also fixed CVE-2026-62832, a publicly disclosed Windows User Profile Service elevation-of-privilege vulnerability.
This flaw has a CVSS score of 7.8 and is caused by improper link resolution before file access.
According to Microsoft, an authenticated attacker with credentials for another local account could run a specially crafted application to load another user's registry hive.
Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges.
Microsoft says CVE-2026-62832 has not been observed in active attacks, but it classifies exploitation as “More Likely.”
Microsoft also announced that KB5121003 continues the rollout of replacement Secure Boot certificates to supported Windows devices.
The company began updating these certificates because Secure Boot certificates used by many Windows systems started expiring in June 2026. Microsoft says the latest update expands the number of eligible devices that can automatically receive the newer certificates through Windows Update.
The cumulative update also upgrades several Windows AI components, including Image Search, Content Extraction, Semantic Analysis, and the Settings Model, to version 1.2605.856.0.
It also includes servicing stack update KB5123304, which is designed to improve the reliability of the Windows update process.
Microsoft says it is currently unaware of any known issues with KB5121003.
Windows 11 users should install the update as soon as possible due to the active exploitation of CVE-2026-68820.
Users can install the updates through Settings > Windows Update > Download & install all.

A system restart is required to complete the update. Users are also advised to back up important data in advance to reduce the risk of data loss if the installation encounters any issues.







Leave a Reply