Microsoft’s 11 August release fixed around 400 vulnerabilities by BleepingComputer’s count (SecurityWeek counts 421), 42 of them Critical. The exploited zero-day, CVE-2026-68820, is a use-after-free privilege escalation in the WinSock driver (AFD), which Lazarus used to deploy its FudModule rootkit. Two more flaws were publicly disclosed before a fix was available: CVE-2026-62832 in the User Profile Service and CVE-2026-72971 in the Container Isolation FS Filter Driver.
The critical remote code execution bugs are the ones to note if you still run servers on site: Active Directory Certificate Services (CVE-2026-62818), DNS Server (including CVE-2026-62817, CVE-2026-62820, CVE-2026-62878 and CVE-2026-65789) and DHCP Server (CVE-2026-62823). Those are the services a typical on-premises domain controller runs.
Laptops mostly patch themselves these days. Servers often don’t, because someone has to schedule the reboot. Make sure your domain controllers and file servers took the August updates, and if an on-premises domain controller exists mainly out of habit, it may be time to ask whether Entra ID can carry the identity load instead.
