HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Use‑After‑Free in Windows Ancillary Function Driver (CVE‑2026‑68820) Triggers CISA KEV Deadline

CVE‑2026‑68820, a use‑after‑free flaw in Windows' afd.sys driver, is actively exploited and listed in CISA's KEV catalog. It demands a patch plus a reboot, forcing organizations to prove remediation within 3‑14 days. For SOC 2‑ready firms, the key is capturing verifiable evidence of both install and reboot to satisfy audit controls.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 blog.qualys.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
blog.qualys.com

Critical Use‑After‑Free in Windows Ancillary Function Driver (CVE‑2026‑68820) Triggers CISA KEV Deadline

What It Is — CVE‑2026‑68820 is a use‑after‑free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows a low‑privilege attacker to execute arbitrary code as SYSTEM. Microsoft rates it Important with a CVSS 7.0 score and it is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitability — Actively exploited in the wild; a crafted application can gain SYSTEM without any user interaction. No workaround exists; remediation requires installing the August cumulative update (KB5121003 or KB5120249) and rebooting the endpoint.

Affected Products — Microsoft Windows 10 (Extended Security Updates) and Windows 11 devices that include the afd.sys driver (essentially all supported Windows endpoints).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping & Evidence – SOC 2 requires documented evidence that critical patches are applied and that remediation is verified; a reboot‑only fix creates a gap that must be tracked.
  • Continuous Monitoring – Real‑time verification that the patch is both installed and the endpoint has rebooted satisfies the “System Operations” and “Change Management” criteria of the Trust Services Criteria.
  • Audit Trail – Demonstrating adherence to CISA BOD 26‑04 timelines (3‑day for internet‑facing, 14‑day for internal) provides a defensible posture for external auditors and enterprise customers.

Recommended Actions

  • Prioritize deployment of KB5121003 (Win 11) or KB5120249 (Win 10) via an automated patching solution.
  • Enforce a mandatory reboot after installation and capture reboot confirmation as immutable log data.
  • Use a reliability‑scoring tool (e.g., Qualys TruRisk Eliminate) to validate that the patch is applied and the system is no longer vulnerable before the CISA deadline.
  • Map the patch‑install + reboot sequence to SOC 2 CC6.1 (System Operations) and CC7.2 (Change Management) controls, storing the evidence in a centralized compliance repository.

Source: Qualys Blog – CVE‑2026‑68820 KEV BOD 26‑04 Requirements

📰 Original Source
https://blog.qualys.com/product-tech/2026/08/18/cve-2026-68820-kev-bod-26-04-requirements

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →