tlder@devMicrosoft's 421-CVE Patch Tuesday leads with a WinSock zero-day under active attack
tlder@dev:~$
Security/CVEs/Advisories

Microsoft's 421-CVE Patch Tuesday leads with a WinSock zero-day under active attack

  • Shipped
  • Action required
  • High importance

Patch Tuesday came in heavy this month. Microsoft shipped fixes for 421 vulnerabilities, 62 of them critical, spread across Windows, Office, SharePoint, Exchange, and Azure. Three are zero-days: two were publicly disclosed before the drop, and one — CVE-2026-68820 — is already being exploited. It's a use-after-free in the Ancillary Function Driver for WinSock (afd.sys), and it hands a local attacker SYSTEM. Patch that one first. The critical remote-code bugs deserve a second look. CVE-2026-62815 is a QUIC flaw at CVSS 9.8 — an unauthenticated attacker sends a crafted packet and runs code. CVE-2026-62878 is a stack overflow in Windows DNS with the same unauthenticated-over-the-network shape, and CVE-2026-64898 is an Office RCE that only needs a victim to open a file. The two publicly-disclosed zero-days, CVE-2026-72971 (unionfs.sys, container isolation) and CVE-2026-62832 (User Profile Service), are elevation-of-privilege rather than remote, so they rank below the WinSock bug. Roll the whole set out; put afd.sys and the network-facing RCEs at the front of the queue.