HomeBlog › Blog

Blog

Critical In-the-Wild Exploit Targets Windows 11, Windows 10, and Windows Server: Action Steps You Need to Take

A significant security issue has been addressed in Windows 11, Windows 10, and Windows Server following a recently detected exploit that is currently taking place in the wild. Microsoft released an emergency patch as part of its August Patch Tuesday updates, specifically targeting the vulnerability designated CVE-2026-68820, which pertains to the Windows Ancillary Function driver for WinSock.

This bug is classified with a high severity rating, evidencing a CVSS score of 7.0 / 6.1. It affects multiple versions of Windows: Windows 10 (from versions 1607 to 22H2), Windows 11 (from versions 23H2 to 26H1), and Windows Server editions spanning from 2012 to Server 2025. Admins are strongly encouraged to implement the available updates without delay due to the active exploitation of this vulnerability.

The exploit allows a locally authenticated attacker to run a program that can trigger the flaw without requiring user interaction. If successfully executed, this could enable attackers to elevate their access privileges to SYSTEM level.

While Microsoft has indicated the complexity of executing a successful attack—suggesting that attackers must prepare their approach to exploit the vulnerability effectively—it has been confirmed that such exploitation has already occurred.

For more details on this vulnerability and to obtain the necessary updates, administrators can reference the MSRC page at Microsoft Security Response Center.

Given the nature of this vulnerability, immediate action is required. No alternative workarounds or registry modifications have been provided by Microsoft, emphasizing the necessity for the patch installation. As part of this update, the vulnerability was initially uncovered with help from two security researchers from Checkpoint.

Put this guide to work on a fast VPS

Deploy a pure-NVMe Windows or Linux VPS in minutes — full admin access, instant setup, from $6/mo.