DIRAS TAKE
Urgently prioritize remediation: CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog with a required action date of 2026-08-25, so apply vendor updates or mitigations immediately for exposed assets.
What is CVE-2026-68820?
Local, authorized users can elevate privileges on Windows systems via a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820). Affected builds include multiple Windows 10 and Windows 11 branches and Windows Server 2012 as listed by the vendor (for example Windows 10 10.0.14393 before 10.0.14393.9418 and Windows 11 10.0.22631 before 10.0.22631.7517); an attacker needs local access and an account to trigger the vulnerability. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows Ancillary Function Driver for WinSock are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7663 | 10.0.19044.7663 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7663 | 10.0.19045.7663 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9168 | 10.0.26100.9168 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9168 | 10.0.26200.9168 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2704 | 10.0.28000.2704 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
Is CVE-2026-68820 being exploited?
CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities catalog on 2026-08-11, requiring U.S. federal agencies to address it by 2026-08-25. Public exploit code is available.
How to fix CVE-2026-68820
- Apply Microsoft updates that contain the listed fixes (install the fixed builds shown in the vendor's affected list).
- Prioritize endpoints running the affected Windows 10, Windows 11, and Windows Server 2012 builds for patching.
- If immediate patching is not possible, restrict local and remote access to affected systems and monitor for suspicious local privilege escalation activity.
- Follow vendor guidance and CISA KEV instructions for mitigation and verification.
Frequently asked questions
Is CVE-2026-68820 being actively exploited?
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog on 2026-08-11 and public exploit code is available.
Which Windows Ancillary Function Driver for WinSock versions are affected by CVE-2026-68820?
Multiple Windows 10 and Windows 11 branches and Windows Server 2012 builds are affected; examples include Windows 10 10.0.14393 before 10.0.14393.9418 and Windows 11 10.0.22631 before 10.0.22631.7517 as listed by the vendor.
Is there a patch for CVE-2026-68820?
Yes; Microsoft published fixes for the affected builds—install the vendor-provided fixed build numbers shown in the affected list.
Does CVE-2026-68820 require authentication?
Yes; the vulnerability requires an authorized local user to trigger a use-after-free that leads to privilege elevation in the WinSock ancillary driver.
References
- nvd.nist.gov/vuln/detail/CVE-2026-68820
- cve.org/CVERecord?id=CVE-2026-68820
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-68820
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026