Patch Tuesday August 2026 delivered a series of critical security updates and threat disclosures, headlined by zero day exploits affecting Windows, Cisco Secure Firewall, and Fortinet VPN products. The scope and urgency of these vulnerabilities make this a priority event for UK businesses relying on Microsoft, Cisco, and Fortinet solutions.
August 2026 Patch Tuesday: A Record Release with Active Threats
On 11 August 2026, Microsoft published its largest Patch Tuesday to date, addressing between 394 and 421 CVEs across its product range. This included multiple critical vulnerabilities, with a particular focus on actively exploited flaws in Windows and related technologies. The most severe was CVE-2026-68820, a Windows kernel zero day, confirmed as being used in the wild by the Lazarus group as part of targeted attacks.
- Release date: 11 August 2026
- Key vulnerabilities fixed: CVE-2026-68820 (Windows kernel), CVE-2026-70329 (Outlook RCE)
- Exploitation status: CVE-2026-68820 exploited in the wild; CVE-2026-70329 not yet observed exploited
The scale of this Patch Tuesday reflected the urgent need to address vulnerabilities across widely deployed Microsoft platforms, including Windows, Microsoft 365 Apps, Office 2019, and Outlook 2016. Notably, the Outlook remote code execution flaw (CVE-2026-70329) was rated CVSS 8.8, though exploitation was assessed as unlikely at the time of release.
Windows Kernel Zero Day Abused by Lazarus Group
The most high-profile vulnerability from August’s release, CVE-2026-68820, affects the Ancillary Function Driver for WinSock (AFD.sys) in all supported Windows platforms. The flaw is classed as a use after free bug, likely triggered by a race condition during socket state handling. Exploitation enables local privilege escalation to SYSTEM, providing attackers with full control over affected endpoints.
North Korea’s Lazarus group exploited this vulnerability in a targeted campaign dubbed Operation Dream Job. They used it to deploy an upgraded version of their FudModule rootkit, which blinds security monitoring and facilitates data theft and further compromise. The campaign targeted organisations in defence, aerospace, and aviation industries across Europe, India, and Brazil, using fake recruiter lures and trojanised PDF viewers to gain initial access.
- Vulnerability: CVE-2026-68820 (Windows AFD.sys)
- Attack method: Local privilege escalation via kernel exploitation
- Threat actor: Lazarus group (North Korea)
- Observed impact: Deployment of FudModule rootkit, SYSTEM-level access, security tool evasion
Microsoft released a fix as part of the August Patch Tuesday updates. CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalogue, marking it as a priority for remediation. Organisations should apply the relevant cumulative updates and restart systems to load the patched driver.
Cisco ASA and FTD Zero Day: Remote Access VPN Under Attack
Cisco disclosed and patched CVE-2026-20349, a critical vulnerability in Cisco Secure Firewall ASA and Secure Firewall Threat Defense (FTD) software. The bug lies in the Remote Access SSL VPN service and is caused by insufficient error checking when processing HTTP requests. An unauthenticated remote attacker can exploit this flaw to trigger a device reload, resulting in denial of service.
- Affected products: Cisco ASA and FTD with Remote Access SSL VPN, IKEv2 Remote Access VPN, or Zero Trust Network Access enabled
- Attack method: Crafted HTTP requests lead to device reload (denial of service)
- Impact: Loss of availability on perimeter firewalls, no user authentication required
- Remediation: Upgrade to fixed ASA trains or apply FTD hotfix images. No workarounds are available.
Cisco confirmed exploitation of this vulnerability in the wild, and CISA added it to its KEV catalogue on 11 August 2026. Organisations using Cisco firewalls for remote access should update immediately to prevent denial of service scenarios that could disrupt business operations.
Fortinet Authentication Bypass: Gunra Ransomware Campaign
Separately, a joint advisory from US and South Korean agencies detailed the Gunra ransomware group’s exploitation of Fortinet authentication bypass vulnerabilities, specifically CVE-2024-55591 and CVE-2025-24472. Gunra, a ransomware-as-a-service operation, leverages these flaws to bypass multi-factor authentication on FortiOS and FortiProxy devices, gaining super admin access and establishing persistence within networks.
- Vulnerabilities: CVE-2024-55591 (Node.js websocket module), CVE-2025-24472 (CSF proxy requests)
- Affected versions: FortiOS 7.0.0-7.0.16, FortiProxy 7.0.0-7.0.19/7.2.0-7.2.12 (CVE-2024-55591); FortiOS 7.0.0-7.0.16, FortiProxy 7.2.0-7.2.12/7.0.0-7.0.19 with Security Fabric enabled (CVE-2025-24472)
- Attack chain: Authentication bypass, admin account creation, lateral movement, data exfiltration, and ransomware deployment
- Remediation: Upgrade FortiOS to 7.0.17+ and FortiProxy to 7.2.13/7.0.20+ as per Fortinet PSIRT guidance
CISA published indicators of compromise (IOCs) as downloadable STIX packages to help organisations detect Gunra activity. NHS England also issued warnings to UK healthcare operators, highlighting the widespread risk.
Why These Zero Days Matter Now
These vulnerabilities are actively exploited in the wild and directly impact core technologies used by UK businesses. Attackers can bypass authentication, disrupt services, or gain SYSTEM-level access, raising the risk of ransomware, data theft, and operational outages.
Mitigation Steps for Organisations
- Apply August 2026 cumulative Windows updates to all supported endpoints and servers.
- Update Cisco ASA and FTD devices to fixed versions if Remote Access VPN features are enabled.
- Upgrade Fortinet FortiOS and FortiProxy appliances to the latest secure builds and monitor for suspicious admin activity.
- Review published IOCs from CISA and Fortinet advisories for signs of compromise.
Staying current with vendor advisories and prioritising patching of exploited vulnerabilities remains critical for reducing exposure to ransomware and targeted attacks.
Originally reported by cybersecuritynews.com.






