Microsoft Patch Tuesday August 2026 Fixes Actively Exploited Zero‑Day and Wormable DNS RCE (CVE‑2026‑68820, CVE‑2026‑62878)
What Happened — Microsoft’s August 2026 Patch Tuesday addressed 398 CVEs across Windows, Office, Azure, Exchange, and other products. Among them, CVE‑2026‑68820 (a use‑after‑free in the Windows Ancillary Function Driver for WinSock) is being actively exploited, and CVE‑2026‑62878 is a critical, wormable remote‑code‑execution flaw in Windows DNS Server that requires no authentication.
Why It Matters for Compliance & Audit Readiness
- The scenario exemplifies a control‑gap in patch‑management that SOC 2 audits expect organizations to remediate promptly (CC6.1 – “The entity implements security patches in a timely manner”).
- Demonstrating continuous evidence of patch deployment is essential to prove due diligence and to avoid audit findings related to unaddressed vulnerabilities.
- Verisq’s Control Mapping capability helps map these patch‑management activities to SOC 2 controls and automatically collect the evidence auditors require.
Who Is Affected — Any organization that runs Windows Server, Windows client OS, or Azure services—spanning finance, healthcare, retail, manufacturing, and SaaS providers.
Recommended Actions
- Deploy the August 2026 updates immediately, prioritizing CVE‑2026‑68820 and CVE‑2026‑62878 on internet‑facing systems.
- Verify patch installation through automated inventory tools and retain logs as audit evidence.
- Map the patch‑management process to SOC 2 CC6.1 and CC6.2 controls; capture screenshots, change‑management tickets, and compliance reports.
- Review and tighten network segmentation for DNS servers to limit exposure while patches are applied.
Source: Security Affairs
Technical Notes
- CVE‑2026‑68820 – Use‑after‑free in
afd.sys; local privilege escalation to SYSTEM; exploit maturity “Unproven” but actively exploited. - CVE‑2026‑62878 – Stack‑based buffer overflow in Windows DNS Server; remote, unauthenticated RCE; wormable.
- Additional RCE bugs: CVE‑2026‑62893 (WDS TFTP), CVE‑2026‑62815 (QUIC), CVE‑2026‑59124 (HPC Pack).
Source: Microsoft Security Advisory