๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
Summary
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability (a bug where software tries to access memory that has already been freed), allowing an authorized attacker to gain higher-level access on a local computer. This vulnerability is actively being exploited in real-world attacks.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions and CISA's BOD 26-04 guidance on prioritizing security updates. For cloud services, follow applicable BOD 26-04 guidance or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and ensure adherence to BOD 26-04 patching guidelines by the due date of 2026-08-25. Consult the Microsoft Security Response Center advisory at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2026-68820 for specific patches or updates.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
August 10, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-68820
First tracked: August 11, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%