Published Wednesday, August 12, 2026 at 10:34 AM PT

BLUF: CVE-2026-68820, a high-severity privilege escalation vulnerability in Windows AFD.sys (Ancillary Function Driver), was actively exploited by threat actors before Microsoft released a patch in August 2026. Local attackers can escalate to SYSTEM level on unpatched systems. All Windows environments must apply August 2026 security updates immediately.
DETAILS
- Active exploitation confirmed: Attackers were exploiting this zero-day in the wild before Microsoft’s patch became available, indicating mature weaponization
- Privilege escalation to SYSTEM: AFD.sys flaw enables local users to gain kernel-level SYSTEM privileges with unrestricted system control
- High-severity classification: Issued by Microsoft; kernel-level component access amplifies impact and persistence potential
- August 2026 Patch Tuesday remediation: Microsoft addressed the vulnerability in monthly security updates released August 2026
- Scope uncertain: Specific affected Windows versions/builds not detailed in available reporting; assume all systems running vulnerable AFD.sys versions are at risk
IMPACT
- Any local user on an unpatched Windows system can compromise to SYSTEM level
- Post-exploitation: malware persistence, lateral movement, data exfiltration, destructive payload delivery
- Affects all Windows deployments (client and server) worldwide without August 2026 patches
- Active threat with confirmed exploitation in production environments
RECOMMENDED ACTIONS
- Deploy August 2026 Microsoft security patches across all Windows assets (highest priority: servers and critical workstations)
- Scan systems for AFD.sys-related suspicious process creation, privilege escalation artifacts, or elevated child processes from unprivileged contexts
- Enable process auditing and privilege escalation monitoring; alert on local privilege escalation attempts
- Isolate unpatched systems; restrict local user access until patches can be applied
SOURCES
- SOC Prime threat intelligence (active exploitation report)
- Microsoft August 2026 Patch Tuesday
- Confirmed pre-patch real-world exploitation
Recent high-severity events at publish time:

