HIGH: Windows AFD.sys Zero-Day CVE-2026-68820 Exploited by Lazarus
Microsoft patched CVE-2026-68820 on August 11, a use after free elevation of privilege flaw in the Windows afd.sys WinSock driver that North Korea's Lazarus Group exploited as a zero day for roughly five weeks against defense and aerospace targets. CISA added it to the Known Exploited Vulnerabilities catalog the same day with a two week remediation deadline.