Critical Use‑After‑Free in Windows Ancillary Function Driver (CVE‑2026‑68820) Triggers CISA KEV Deadline
What It Is — CVE‑2026‑68820 is a use‑after‑free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a low‑privilege attacker to execute arbitrary code as SYSTEM. Microsoft rates it Important with a CVSS 7.0 score and it is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Exploitability — Actively exploited in the wild; a crafted application can gain SYSTEM without any user interaction. No workaround exists; remediation requires installing the August cumulative update (KB5121003 or KB5120249) and rebooting the endpoint.
Affected Products — Microsoft Windows 10 (Extended Security Updates) and Windows 11 devices that include the afd.sys driver (essentially all supported Windows endpoints).
Why It Matters for Compliance & Audit Readiness
- Control Mapping & Evidence – SOC 2 requires documented evidence that critical patches are applied and that remediation is verified; a reboot‑only fix creates a gap that must be tracked.
- Continuous Monitoring – Real‑time verification that the patch is both installed and the endpoint has rebooted satisfies the “System Operations” and “Change Management” criteria of the Trust Services Criteria.
- Audit Trail – Demonstrating adherence to CISA BOD 26‑04 timelines (3‑day for internet‑facing, 14‑day for internal) provides a defensible posture for external auditors and enterprise customers.
Recommended Actions
- Prioritize deployment of KB5121003 (Win 11) or KB5120249 (Win 10) via an automated patching solution.
- Enforce a mandatory reboot after installation and capture reboot confirmation as immutable log data.
- Use a reliability‑scoring tool (e.g., Qualys TruRisk Eliminate) to validate that the patch is applied and the system is no longer vulnerable before the CISA deadline.
- Map the patch‑install + reboot sequence to SOC 2 CC6.1 (System Operations) and CC7.2 (Change Management) controls, storing the evidence in a centralized compliance repository.
Source: Qualys Blog – CVE‑2026‑68820 KEV BOD 26‑04 Requirements