CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog, warning that the flaw is being exploited in attacks. The issue, tracked as CVE-2026-68820, is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock. An authorized attacker could exploit the issue locally to elevate […] The post CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks app
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeCyber Security News
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
By Abinaya
August 13, 2026
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog, warning that the flaw is being exploited in attacks.
The issue, tracked as CVE-2026-68820, is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock. An authorized attacker could exploit the issue locally to elevate privileges on an affected Windows system.
This means an attacker who already has access to a device with limited permissions may be able to gain higher-level access, including privileges normally restricted to administrators or the operating system.
The vulnerability is associated with CWE-416, a common software weakness known as use-after-free. This class of flaw occurs when a program continues to use memory after it has been released.
Windows Ancillary Function 0-Day Vulnerability Exploited
In some cases, an attacker can manipulate the freed memory space and force the vulnerable component to execute unexpected actions. On Windows, privilege escalation vulnerabilities are especially serious because they can enable attackers to move from an initial foothold to full control of a system.
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog on August 11, 2026, confirming active exploitation and setting August 25, 2026, as the remediation deadline for organizations covered by BOD 26-04.
The directive requires federal civilian executive branch agencies to prioritize security updates based on risk and address vulnerabilities listed in the catalog within the specified deadlines.
Although CISA has confirmed exploitation, it has not stated whether the vulnerability is being used in ransomware campaigns. The ransomware status is currently listed as unknown.
No public technical details about the attacks, threat actors, malware families, or exploitation methods were included in the available advisory information.
Windows privilege escalation flaws often play an important role in broader intrusion chains. An attacker may first gain access through phishing, stolen credentials, a vulnerable public-facing application, or another security weakness.
They can then exploit a local privilege-escalation vulnerability to turn off security controls, access protected files, create administrator accounts, deploy malicious tools, or spread across a network.
Organizations should review Microsoft’s security guidance and apply the available mitigations as soon as possible. Security teams should identify all affected Windows assets, including workstations, servers, virtual machines, and cloud-connected endpoints
They should also verify that patch deployment succeeds and that systems have restarted when required. CISA also recommends following its Forensics Triage Requirements, particularly for systems suspected of compromise.
Teams should review endpoint telemetry for unusual changes in privileges, unexpected administrator account creations, suspicious processes running with elevated permissions, and attempts to turn off endpoint security tools.
The active exploitation status makes CVE-2026-68820 a high-priority patching issue. Organizations that cannot immediately apply vendor mitigations should assess exposure, restrict unnecessary local access, strengthen monitoring, and consider discontinuing use of affected products where no effective mitigation is available.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security News
Microsoft Exchange Server Vulnerabilities Enable DoS, Privilege Escalation, and RCE Attacks
Cyber Security
Trezor ShipMonk Data Breach Exposes Personal Data of Over 13,000 Hardware Wallet Customers
Cyber Security News
North Korean IT Workers Use AI-Forged IDs and Remote Desktops to Become Trusted Employees
Cyber Security News
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
Cyber Security News
Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?