# Microsoft patches Lazarus‑exploited Windows zero‑day CVE‑2026‑68820

**Published:** 2026-08-13T04:48:09.626Z  
**Topic:** Microsoft  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/76dbb3eb-699b-4b55-a7ae-741464589d6f

Microsoft patched CVE‑2026‑68820 on Aug 11 after Check Point found Lazarus using it to deploy the FudModule rootkit. Enterprises must update Windows 11 builds

Microsoft released an August 11 update that closes CVE‑2026‑68820, a kernel‑level zero‑day in the AFD.sys driver that North Korea’s Lazarus group has been exploiting to install its FudModule v3.1 rootkit [2]. The fix arrives after the vulnerability was shown to give attackers SYSTEM privileges, underscoring the urgency for organizations—especially those in defense, aerospace and aviation—to apply the patch immediately.

| At a glance | |
|---|---|
| Vulnerability | CVE‑2026‑68820 (AFD.sys kernel driver) |
| Patch date | August 11, 2026 (August Patch Tuesday) |
| Exploited by | Lazarus group (North Korean threat actor) |
| Rootkit deployed | FudModule v3.1 (kernel‑mode) |

## Active exploitation details  
Check Point Research traced the exploit to two parallel infection chains that begin with malicious PDF viewers delivered via social‑engineering job offers. After a victim opens the PDF, a sideloaded DLL decrypts a payload that runs MISTPEN, a downloader that uses the Microsoft Graph API to fetch additional modules from attacker‑controlled OneDrive storage. The final stage triggers the AFD.sys flaw, granting SYSTEM‑level access and loading FudModule v3.1 [2]. The rootkit disables telemetry callbacks, kills the NT Kernel Logger, and blinds more than 90 ETW providers, while also tampering with Microsoft Defender’s Smart App Control. In earlier versions, a dedicated Defender‑disabling routine existed; the new variant uses a generic suppression engine instead [2].

## Implications for enterprise security  
The August patch follows a record‑breaking July Patch Tuesday that addressed 570 vulnerabilities—almost three times the previous month’s total [1]. The scale of the update highlights Microsoft’s growing backlog of critical bugs, but the active exploitation of CVE‑2026‑68820 shows that zero‑days can remain in the wild for months, as seen in other Lazarus campaigns that have persisted for up to six months before disclosure [3]. Enterprises should not only apply the patch but also audit outbound traffic to Roundcube, WordPress or PrestaShop sites that may be serving as covert relay nodes for the group’s command‑and‑control traffic [2].

## What to watch
- **Patch rollout** – Verify that Windows 11 builds 26100 and 26200 have received the August update across all endpoints.  
- **Relay infrastructure** – Monitor traffic to compromised Roundcube and CMS servers, especially those vulnerable to CVE‑2025‑49113, which Lazarus uses to host its RelayShell web shell.  
- **Future Patch Tuesday** – Watch the September Patch Tuesday for any additional zero‑day fixes, given the recent surge in high‑severity updates.

The August fix closes a critical attack path that let Lazarus move from user‑level compromise to full kernel control, but the group’s use of sophisticated delivery chains and hijacked web infrastructure suggests that detection will remain a challenge until broader network‑level defenses are hardened.

## Sources
1. Forbes — [Microsoft Warns 2 Zero-Days Already Exploited In Attacks: Update Now](https://www.forbes.com/sites/daveywinder/2026/07/15/microsoft-warns-2-zero-days-already-exploited-in-attacks-update-now/)
2. Cybersecuritynews — [Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to...](https://cybersecuritynews.com/windows-afd-sys-zero-day-exploited/)
3. Codelock — [How North Korean Hackers Exploited a Windows Zero-Day Flaw That...](https://www.codelock.it/news/how-north-korean-hackers-exploited-a-windows-zero-day-flaw-that-microsoft-ignored-for-months)

---
Cite as: TrendWatcher, "Microsoft patches Lazarus‑exploited Windows zero‑day CVE‑2026‑68820", https://www.trendwatcher.in/article/76dbb3eb-699b-4b55-a7ae-741464589d6f
