← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE KEV ✓ EPSS 0.06

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…

Číst originál na Qualys →

5 zpráv z 5 zdrojů · první 11. 8. 02:00 · poslední 18. 8. 20:06 CZ · EN/orig

Microsoft US FR

tg: zneužíváno tg: regulace tg: návod tg: propagace

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-68820 7.0 3.1 · microsoft KEV ✓ 0.06

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 7.0.

Jak se o tom psalo 5

  1. · Qualys US nadpis události

    CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

    Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…

  2. · CERT-FR – avis FR

    Multiples vulnérabilités dans Microsoft Windows (12 août 2026)

    De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que la vulnérabilité CVE-2026-68820...

  3. · Tenable Research US

    Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

    42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate…

  4. · Microsoft Security US

    CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  5. · CISA KEV US

    Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (CVE-2026-68820)

    CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft Windows Ancillary Function Driver for WinSock. Remediation due date: 2026-08-25.