Microsoft Patch Batch Puts Exploited Windows Driver First
The Hacker News reported that Microsoft’s August security release covers 398 CVEs, led by an actively exploited Windows afd.sys flaw and followed by four unauthenticated server RCE issues rated 9.8.

Microsoft's August patch cycle is unusually large and immediately operational, The Hacker News reported, with 398 newly assigned CVEs and an already exploited Windows networking-driver flaw, CVE-2026-68820, in afd.sys, the Ancillary Function Driver for WinSock.
The Windows driver issue is not the highest-rated bug in the release.
Its priority comes from exploitation status: an attacker who already has code running on a machine can use the race condition to escalate privileges to SYSTEM.
Exploit Status Drives The First Priority
Microsoft assigned the afd.sys flaw a CVSS score of 7.0 and listed it as the only bug in the batch known to be exploited when the updates shipped.
Check Point Research has linked the zero-day to Lazarus activity in the Operation Dream Job campaign, while public Microsoft material did not name an actor behind the exploitation.
Several other flaws carry higher scores; the driver bug has evidence of real-world use.
Four Server Bugs Sit Close Behind
The next group is made up of remote code execution flaws that need no credentials and no user interaction.
Windows DNS Server, Windows Deployment Services, Microsoft's QUIC implementation and High Performance Computing Pack each received a 9.8 CVSS score, making exposure and service inventory the deciding factors.
The DNS Server issue is a stack-based buffer overflow that the Zero Day Initiative characterized as technically wormable.
The label describes reachability and propagation potential; it does not mean a working worm has appeared.
WDS and QUIC present similar remote-entry concerns where the relevant services are reachable, while HPC Pack is less broadly deployed because it is not installed by default.
SharePoint Gets The Second Half Of A Chain
The release also closes the code-execution side of a SharePoint exploit chain that began with a July authentication-bypass patch.
Rapid7 Labs had disclosed a two-part route involving CVE-2026-55040 and a separate RCE flaw, now identified as CVE-2026-63520.
The July fix broke the demonstrated unauthenticated path by closing the authentication bypass.
The new update still matters for on-premises SharePoint farms because it removes the remaining RCE component rather than leaving defenders dependent on a single earlier fix holding the chain shut.
Patch Order Is Not Just A Scorecard
The release shows why CVSS alone is a poor scheduling tool during a heavy Patch Tuesday.
Active exploitation, exposed services and installed software determine the sequence more cleanly than severity scores alone.
A practical queue starts with the exploited afd.sys vulnerability on Windows systems where privilege escalation would be damaging, then moves to internet-facing or broadly reachable DNS, WDS, QUIC and HPC services.
SharePoint teams should verify both the July authentication-bypass fix and the new RCE fix, because the chain is only fully closed when both sides are patched.




















