← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 12, 2026 · 00:45via CSO Online

Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability

Brief

A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.

The hole is in Windows’ Ancillary Function Driver for WinSock ( CVE-2026-68820 ), which, according to Todd Schell , principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges.

“Exploitation has already been detected,” noted Jack Bicer , director of vulnerability research at Action1, “making this the highest priority vulnerability in this month’s release.”

Separately, SAP issued 29 new and updated security patches, the most severe of which is CVE-2026-58231 , with a CVSS score of 10.

Read more on CSO Online