Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft has released security updates addressing 398 vulnerabilities, including a critical Windows kernel driver flaw currently being exploited in the wild. Security researchers have linked the active exploit to the Lazarus group.
Why it matters
The presence of an actively exploited zero-day vulnerability in core Windows components poses a significant risk to enterprise and individual system security.
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.
The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft has not publicly attributed the exploitation. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in