Virtue Technology Solutions logo

Cybersecurity

August 2026 Vulnerabilities You Should Know About

• Virtue Technology Solutions

Staying on top of the latest vulnerabilities isn't just for enterprises with dedicated security teams. For small and mid-sized businesses, knowing what's being exploited right now is a critical part of maintaining a strong security posture.

August 2026 Vulnerabilities — Kernel Zero-Day and Citrix RCE

August Patch Tuesday: 421 CVEs Fixed

Microsoft's August 2026 Patch Tuesday addressed 421 vulnerabilities across Windows, Office, SharePoint, Azure, .NET, and other products. While slightly smaller than July's record-breaking 622, the month still carried significant risk — including one actively exploited zero-day and two more that were publicly disclosed before fixes shipped.

Among the most important findings:

  • One actively exploited zero-day — a Windows kernel privilege escalation flaw already being used in real attacks
  • Two publicly disclosed zero-days — in the Windows User Profile service and the Container Isolation FS Filter Driver
  • A Citrix NetScaler RCE — initially downplayed as a DoS bug, later shown to allow unauthenticated remote code execution
  • Multiple Windows kernel elevation-of-privilege flaws — several allowing attackers to gain SYSTEM privileges

Zero-Day: Windows Kernel Privilege Escalation (CVE-2026-68820)

CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) — a kernel-mode component that every Windows machine relies on for network communication. Microsoft rated it Important with a CVSS score of 7.0, but it was actively exploited in the wild before a patch was available.

Who's behind it: Check Point Research attributed the exploitation to the Lazarus Group, a North Korea-linked threat actor. During their Operation Dream Job attacks, they used this flaw to gain SYSTEM-level privileges and deploy an upgraded version of their FudModule rootkit — a kernel-mode tool designed to disable security software and hide malicious activity.

What this means for your business: An attacker who already has a foothold on a single workstation — often gained through phishing or a compromised account — can use this vulnerability to escalate to full administrative control of that machine. From there, they can move laterally across your network, steal credentials, and access sensitive data. Because the exploit chain often starts with a phishing email, this ties directly into the phishing defenses every business should have in place.

Two More Publicly Disclosed Zero-Days

Beyond the actively exploited flaw, Microsoft patched two additional zero-days that were publicly disclosed before fixes were available:

  • CVE-2026-62832 — an elevation of privilege vulnerability in the Windows User Profile service that could grant an attacker administrator privileges
  • CVE-2026-72971 — a tampering vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys)

Neither was confirmed as actively exploited, but public disclosure means attackers have a head start on reverse-engineering the flaw. These should be patched with the same urgency as the exploited zero-day.

Citrix NetScaler RCE Under Active Attack (CVE-2026-8452)

CVE-2026-8452 is a vulnerability in Citrix NetScaler ADC and NetScaler Gateway that took a dangerous turn in August. When Citrix first described it in June, it was characterized as a memory overflow capable of causing "unpredictable behavior or denial of service." Security researchers later demonstrated it could actually permit unauthenticated remote code execution as root on internet-facing appliances.

On August 26, 2026, CISA added CVE-2026-8452 to its Known Exploited Vulnerabilities (KEV) catalog after confirming attackers were exploiting it in the wild to deliver web shells. CISA set a federal remediation deadline of August 29.

What this means for your business: If you run customer-managed NetScaler ADC or NetScaler Gateway appliances — common for remote access and application delivery — these are now a prime target. Attackers are scanning for internet-facing instances. Upgrade every affected appliance and virtual server immediately.

Windows Kernel Elevation of Privilege Flaws

August also included multiple elevation-of-privilege vulnerabilities in the Windows Kernel itself, tracked as CVE-2026-61929 and CVE-2026-62788. An attacker who successfully exploited these could gain SYSTEM privileges on an affected machine.

These kernel flaws are particularly concerning because they're often chained with other vulnerabilities — a remote code execution bug to get a foothold, then a privilege escalation flaw like these to gain full control. This is exactly the pattern seen in the Lazarus attacks.

Common Patterns We're Seeing

Across August's vulnerabilities, a few patterns stand out:

  1. Phishing is still the entry point — the exploited kernel zero-day was delivered through Operation Dream Job phishing campaigns
  2. VPN and remote-access appliances are prime targets — Citrix NetScaler joins a long list of edge devices under active attack
  3. Kernel privilege escalation is the common second step — attackers chain remote access with local privilege escalation to gain full control
  4. Public disclosure is nearly as dangerous as exploitation — two of August's zero-days were disclosed before patches, giving attackers a head start

Practical Steps SMBs Can Take This Month

You don't need a massive security budget to stay ahead. Here are actionable steps:

  • Apply the August Patch Tuesday updates immediately — prioritize the afd.sys kernel fix (CVE-2026-68820) and the two disclosed zero-days. Our [managed IT services](/services/it-managed-services) include automated patch management and continuous vulnerability monitoring.
  • Patch or replace Citrix NetScaler appliances — if you run NetScaler ADC or Gateway, upgrade to the fixed version immediately; these are being actively scanned and exploited
  • Reinforce your phishing defenses — since the kernel zero-day was delivered via phishing, review your email security, MFA, and user awareness training
  • Audit for exposed edge devices — ensure VPNs, remote access, and application delivery appliances aren't directly reachable from the internet without proper controls
  • Run a vulnerability scan — even a basic scan can reveal obvious gaps before attackers find them

Conclusion

August 2026 was another reminder that the threat landscape moves fast. An actively exploited Windows kernel zero-day, a Citrix NetScaler RCE under attack, and multiple privilege escalation flaws mean organizations cannot afford to delay patching.

A comprehensive cybersecurity program that includes regular vulnerability assessments, managed detection and response, and compliance-aligned controls can keep your business protected without requiring a dedicated internal security team.

Need help assessing your current vulnerability management program? Contact Virtue Technology Solutions for a no-pressure consultation.

Need help with your IT strategy?

We help businesses plan, secure, and manage their technology. Reach out for a no-pressure conversation.