The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog, warning that the flaw is being exploited in attacks.
The issue, tracked as CVE-2026-68820, is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock. An authorized attacker could exploit the issue locally to elevate privileges on an affected Windows system.
This means an attacker who already has access to a device with limited permissions may be able to gain higher-level access, including privileges normally restricted to administrators or the operating system.
The vulnerability is associated with CWE-416, a common software weakness known as use-after-free. This class of flaw occurs when a program continues to use memory after it has been released.
Windows Ancillary Function 0-Day Vulnerability Exploited
In some cases, an attacker can manipulate the freed memory space and force the vulnerable component to execute unexpected actions. On Windows, privilege escalation vulnerabilities are especially serious because they can enable attackers to move from an initial foothold to full control of a system.
CISA added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog on August 11, 2026, confirming active exploitation and setting August 25, 2026, as the remediation deadline for organizations covered by BOD 26-04.
The directive requires federal civilian executive branch agencies to prioritize security updates based on risk and address vulnerabilities listed in the catalog within the specified deadlines.
Although CISA has confirmed exploitation, it has not stated whether the vulnerability is being used in ransomware campaigns. The ransomware status is currently listed as unknown.
No public technical details about the attacks, threat actors, malware families, or exploitation methods were included in the available advisory information.
Windows privilege escalation flaws often play an important role in broader intrusion chains. An attacker may first gain access through phishing, stolen credentials, a vulnerable public-facing application, or another security weakness.
They can then exploit a local privilege-escalation vulnerability to turn off security controls, access protected files, create administrator accounts, deploy malicious tools, or spread across a network.
Organizations should review Microsoft’s security guidance and apply the available mitigations as soon as possible. Security teams should identify all affected Windows assets, including workstations, servers, virtual machines, and cloud-connected endpoints
They should also verify that patch deployment succeeds and that systems have restarted when required. CISA also recommends following its Forensics Triage Requirements, particularly for systems suspected of compromise.
Teams should review endpoint telemetry for unusual changes in privileges, unexpected administrator account creations, suspicious processes running with elevated permissions, and attempts to turn off endpoint security tools.
The active exploitation status makes CVE-2026-68820 a high-priority patching issue. Organizations that cannot immediately apply vendor mitigations should assess exposure, restrict unnecessary local access, strengthen monitoring, and consider discontinuing use of affected products where no effective mitigation is available.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks appeared first on Cyber Security News.



