Microsoft on August 12 released its August 2026 Patch Tuesday, fixing 421 vulnerabilities across Windows, Office, Azure, Edge, SQL Server, and Visual Studio — 11 rated critical and 99 rated important. Among the fixes is a Windows Ancillary Function Driver (AFD) zero-day, tracked as CVE-2026-38147, that has been actively exploited by Lazarus-linked actors since at least mid-July, according to Microsoft's Threat Intelligence Center and CISA's August 18 advisory update.
What the AFD Zero-Day Does
The Ancillary Function Driver is a long-standing Windows kernel component that brokers socket operations between user-mode applications and the Windows networking stack. The vulnerability allows a local attacker to escalate privileges to SYSTEM by sending crafted input to the AFD syscall interface — a class of escalation that is particularly dangerous in containerized environments where an attacker who has gained a foothold inside a container can use the AFD bug to break out into the host. Microsoft confirmed in-wild exploitation by Lazarus — the North Korean state-affiliated threat actor — and several ransomware affiliates that Microsoft tracks as ITW (In-The-Wild) targets. The fix ships as a kernel-mode patch and requires a reboot to apply.
The Broader August Patch Context
The August Patch Tuesday comes against a heavy August threat landscape. Per Hoplon Infosec's August 2026 cybersecurity roundup, the month also saw ShieldBreak — a new malware loader tied to Lazarus — and the Gunra ransomware, which Bitdefender and Daily Security Review reported on August 12 actively exploiting Fortinet FortiGate and Schneider Electric Modicon flaws to bypass multi-factor authentication. Gunra's MFA-bypass capability, in particular, puts pressure on industrial-control and remote-access deployments that depend on FortiGate for VPN termination. Microsoft additionally released updates for Microsoft Edge that fix three Chromium-engine CVEs, including one rated critical.
CISA's August 18 CVE Brief
CISA's August 18 CVE Brief added the AFD zero-day to its Known Exploited Vulnerabilities catalog with a remediation deadline of September 8 for federal agencies, and listed 42 additional critical issues and 95 high-priority updates that organizations should triage this month. The Brief also flagged two additional actively exploited issues disclosed by third-party vendors — Cisco's August 19 PSIRT advisory published 10 advisories including a CVSS 10.0 critical affecting Cisco Crosswork Security, and Fortinet's mid-month PSIRT update that addresses the authentication bypass that Gunra is exploiting in the wild.
What Defenders Should Prioritize
Microsoft's Patch Tuesday guidance, reinforced by CISA's Brief, prioritizes the following within 24 to 48 hours: the Windows AFD zero-day (CVE-2026-38147); the two Critical-rated RCE issues in Windows Hyper-V and the Windows TCP/IP stack; the Azure Bastion privilege-escalation issue disclosed in the same release; and the Office memory-corruption issue affecting Word and Outlook. The Fortinet FortiGate authentication bypass should be patched within seven days, and the Gunra ransomware IOCs should be deployed to EDR and SIEM detection rules as a priority.
How August Fits the Bigger Picture
Ransom-DB's weekly ransomware threat intelligence report for the week ending August 15 recorded 317 ransomware victim claims across global leak sites — a 112.8 percent week-on-week increase that pushed August above the elevated operational velocity observed throughout the summer. Combined with the Lazarus AFD exploitation, the Gunra FortiGate bypass, and the Medusa advisory that CISA, the FBI, and HHS published on August 18 (covered separately), August 2026 is shaping up as one of the heavier defensive months of the year. The next major patch wave lands September 8.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.