preloader

· · devops digital-security microsoft windows cve patch-management zero-day vulnerability-management europe azure

Microsoft Patched 421 Flaws This Week, But the One North Korea Was Already Using for Two Months Is the One That Matters

Source: The Register

A patch release is only as useful as a team’s ability to act on it, and this month Microsoft has handed out 421 reasons to act, with two that cannot wait until next week.

A zero-day that predates its own patch by two months

CVE-2026-68820 is a use-after-free flaw in the Windows Ancillary Function Driver for WinSock, afd.sys, that lets a local attacker with a foothold elevate to SYSTEM privileges. Microsoft’s advisory confirms it was exploited in the wild before today’s fix existed. Check Point researchers Moshe Marelus and David Driker, credited with the discovery, say they first observed North Korea’s Lazarus Group using it back in early June, meaning attackers had a working privilege escalation chain for roughly two months while defenders had nothing to patch against. If your endpoint detection has not been specifically checked against this pattern, assume it has had a blind spot since June.

The second flaw to act on immediately is CVE-2026-62832, an improper link resolution bug in Windows User Profile Service that also allows local privilege escalation. Microsoft has not confirmed active exploitation yet but has flagged it as publicly disclosed, the category that reliably turns into working exploit code within days once technical details are circulating.

The other 419 are still a real problem

Of the 421 vulnerabilities fixed this month, 236 are in Windows itself, 98 in Office, 30 in SharePoint Server, 26 in developer tools, 17 in Azure, and 7 in Exchange Server. Sixty-two are rated critical, and 40 of those are remote code execution flaws. On Azure specifically, CVE-2026-71331 is a critical RCE in the Azure Attestation and Device Health Attestation services, worth checking against any workload that relies on attestation for compliance or confidential computing guarantees.

A list this size cannot be triaged, tested, and deployed on a normal weekly cadence, and treating all 421 as equally urgent is how the two that are already being exploited end up buried in a spreadsheet behind 400 that are not.

What European teams should prioritise this week

Patch CVE-2026-68820 and CVE-2026-62832 first, on every endpoint, ahead of the rest of the queue. Then work through the 40 critical RCE flaws in order of internet exposure and check whether any Azure Attestation dependent workloads need the Azure-side fix applied on top of the endpoint patches. Under NIS2 and DORA, a confirmed-exploited privilege escalation sitting unpatched past a reasonable window is both an operational and a regulatory problem, and regulators increasingly expect evidence of a documented triage decision, not just an eventual patch.

If your organisation needs help prioritising a release of this size, confirming exposure to CVE-2026-68820 or CVE-2026-62832, or building a patch cadence that can separate the two flaws that matter from the 419 that can wait, contact Excello Digital. We help European IT teams turn an overwhelming CVE list into a triage plan they can actually execute.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!