CISA adds Windows WinSock driver vulnerability to the KEV Catalog
CISA added CVE-2026-68820, a Microsoft Windows Ancillary Function Driver for WinSock use-after-free vulnerability, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 25, 2026 applies to federal agencies, not to private businesses.
- Official source
- Cybersecurity and Infrastructure Security Agency ↗
- Jurisdiction
- United States
- Publication date
- August 11, 2026
- Legacy Core review
- August 17, 2026 · Christopher Green
- Source checked
- August 17, 2026
- Affected sectors
- Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
- Deadline date
- August 25, 2026
Summary
CISA added CVE-2026-68820, a Microsoft Windows Ancillary Function Driver for WinSock use-after-free vulnerability, to its Known Exploited Vulnerabilities Catalog on August 11, 2026. The catalog due date of August 25, 2026 applies to federal agencies, not to private businesses.
Why it matters
Windows is common in small offices. CISA listed this flaw because it has evidence of active exploitation; a local privilege-escalation issue can let someone who already has a login gain more control of the machine. Catalog inclusion does not mean a particular firm is affected.
Recommended action
Ask your IT owner or managed service provider whether August 2026 Windows updates covering CVE-2026-68820 were deployed. Keep the response with your security-maintenance records.