Microsoft's recent security updates addressed a significant vulnerability, CVE-2026-68820, in a core Windows kernel driver that is being actively exploited, allowing attackers to escalate privileges to SYSTEM level. This vulnerability has a CVSS score of 7.0 and is the only one flagged as under active exploitation. Check Point Research links it to the Lazarus group.
Additionally, four other vulnerabilities included in the update do not require victim action:
- CVE-2026-62878: A stack-based buffer overflow in Windows DNS Server, considered wormable.
- CVE-2026-62893: A remote flaw in Windows Deployment Services through TFTP handling.
- CVE-2026-62815: A vulnerability in Microsoft QUIC allowing remote code execution.
- CVE-2026-59124: An important flaw in HPC Pack with a CVSS score of 9.8.
The updates also finalized a fix for a SharePoint vulnerability chain, with CVE-2026-55040 addressing an authentication bypass and CVE-2026-63520 fixing the code execution component. Organizations are advised to prioritize patching CVE-2026-68820 and then address the other vulnerabilities, ensuring SharePoint installations have both fixes applied.