Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Automated news aggregation. Headlines and summaries are gathered from public feeds; see our editorial standards for sourcing, corrections, and AI-assist disclosure.

Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only
Key takeaways
- 01Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
- 02The bug sits in a core Windows kernel driver that handles network socket operations.
- 03An attacker with code already running on a machine can use it to escalate to SYSTEM.
About this story
This story was aggregated from The Hacker News. Headlines, summaries, and links are gathered automatically from public RSS feeds for your convenience.
Read the full story →