CISA added Windows CVE-2026-68820 to its Known Exploited Vulnerabilities catalog on August 11, 2026. Microsoft identifies the issue in the Windows Ancillary Function Driver for WinSock. A successful attack requires local authorized access, but the impact can raise permissions on an affected system. Treat the August update cycle as priority maintenance for Windows servers, hosting control systems, identity services, Hyper-V hosts, and other shared administration systems.
Microsoft August update references
Use Microsoft Update, WSUS, Intune, or your established enterprise servicing workflow to deploy the supported August cumulative update for each release. Microsoft lists these Windows Server references for the current fix:
| Windows Server release | August update reference |
|---|---|
| Windows Server 2016 | KB5120418 |
| Windows Server 2019 | KB5120238 |
| Windows Server 2022 | KB5120242 |
| Windows Server 2025 | KB5120233 |
Windows Server 2012 and 2012 R2 require an active Extended Security Updates entitlement for current security servicing. Do not mistake an unsupported or unentitled system for a patched one; plan its supported migration or compensating access restrictions with the system owner.
Patch servers in the right order
- Inventory affected Windows servers and identify their service roles, maintenance windows, restart dependencies, and customer impact.
- Assign an owner, maintenance communication, and recovery decision point before approving the change.
- Deploy the applicable Microsoft update through the established servicing tool. Keep the version and update result with the change record.
- Restart when required, following the documented order for clustered, identity, virtual-host, database, and hosting-control workloads.
- Validate the operating-system build, core services, monitoring, and a small representative application workflow before closing the change.
Special checks for hosting and infrastructure teams
- For IIS and application servers, confirm websites, application pools, certificates, scheduled work, and monitoring return normally.
- For Hyper-V and virtualization hosts, use the established cluster-aware maintenance process and confirm host, guest, and management health after restart.
- For identity and file services, coordinate restarts to preserve authentication, directory replication, policy processing, and customer access.
- For remote administration systems, keep approved administrator access available while reducing unnecessary local access on sensitive servers.
Review access after the update
The update reduces the reported risk but does not determine whether a system was accessed earlier. Use your normal incident-review process to investigate unexpected privileged-account activity, unusual local administrative changes, or alerts that need escalation. Keep that evidence with the approved security process rather than adding private detail to a maintenance ticket.
