August's Windows update fixes a flaw hackers were already using - install it now
Microsoft's August 2026 update landed on the 11th, and it's another big one: fixes for more than 400 flaws across Windows, Office and other products. The one that matters most is a hole attackers were already crawling through before the patch existed.
It's tracked as CVE-2026-68820, a bug in a low-level Windows networking driver (afd.sys, the piece that handles Windows Sockets). On its own it doesn't break into your PC from the outside - an attacker needs a foothold first - but once they're in, it lets them climb from an ordinary account all the way up to SYSTEM, the highest level of control Windows has. Check Point traced the attacks to North Korea's Lazarus group, active since at least July, and the US government's CISA has added it to its official must-patch list. Two other flaws were publicly disclosed before the fix shipped, which raises the odds someone else picks them up.
For home users the takeaway is simple: install this one, don't sit on it. On Windows 11 the update is KB5121003 - open Settings > Windows Update and hit "Download & install." Take thirty seconds to create a restore point first, in case the update itself misbehaves; the last few months have had their share of update hiccups.
Tendvane can confirm the update actually installed, and if Windows Update jams partway - a common cause of a patch that's "stuck at 100%" - its Windows-Update repair wizard clears the usual blockages so the fix goes through.