By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Microsoft Patches 398 Vulnerabilities, Including Active Zero-Day

Microsoft released its monthly security updates on Tuesday, addressing a total of 398 vulnerabilities across its product lines. Among these, one critical flaw, tracked as CVE-2026-68820, was already being actively exploited by attackers in the wild. This zero-day vulnerability resides within a core Windows kernel driver responsible for network socket operations. Exploitation of this bug allows an attacker who has already gained code execution on a target machine to escalate their privileges to the highest level, SYSTEM. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.0, indicating a high severity. Microsoft prioritized the patch for this actively exploited flaw, releasing it as part of its regular security update cycle.
The broader set of patches released by Microsoft covers a wide range of its software, including Windows operating systems, Microsoft Office, Azure, and other enterprise products. The sheer volume of vulnerabilities addressed underscores the ongoing challenges in maintaining robust security across complex software ecosystems. While the zero-day vulnerability is the most pressing concern due to its active exploitation, the other 397 flaws also represent potential risks to users and organizations if left unpatched. These vulnerabilities could range from information disclosure and denial-of-service to remote code execution, depending on their specific nature and the affected component.
Microsoft's monthly "Patch Tuesday" is a critical event for IT administrators and security professionals worldwide, as it provides essential fixes for known security weaknesses. Users and organizations are strongly advised to apply these updates as soon as possible to mitigate the risks associated with these newly disclosed and already exploited vulnerabilities. The proactive patching of the CVE-2026-68820 zero-day demonstrates Microsoft's commitment to addressing immediate threats, but the ongoing discovery of numerous other flaws highlights the persistent need for vigilance and timely security hygiene. The company's security response process involves identifying, assessing, and developing patches for vulnerabilities, with a particular focus on those that pose the greatest risk to users, such as actively exploited zero-days. The successful deployment of these patches is crucial for maintaining the integrity and security of systems running Microsoft software.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.