JPCERT/CC, Japan's coordination centre for computer security incidents, told Japanese organisations on 12 August to apply Microsoft's August updates, relaying Microsoft's confirmation of in-the-wild exploitation of CVE-2026-68820 1. The flaw sits in the Windows Ancillary Function Driver for WinSock, the kernel component through which Windows applications reach the network stack, and it allows elevation of privilege.
Elevation of privilege rarely opens the door. It is what an attacker uses after a phishing attachment or a stolen session has already put code on the machine with ordinary user rights, to move from that account to full control of the host. A driver running in the kernel is the shortest available route, which is why this class of flaw turns up in exploit chains rather than headlines.
The attribution chain here is worth stating plainly, because it runs three deep and is often written as one. Microsoft observed the exploitation and said so; JPCERT/CC relayed that to Japanese organisations with its own advice attached; this briefing reports the relay. Nothing in the alert is Japan's own detection, and JPCERT/CC does not claim otherwise.
Microsoft's monthly release remains the instrument the whole industry patches to, and it does not always arrive complete. In June the same cycle fixed roughly 200 flaws including six zero-days, and shipped an overdue Exchange patch sixteen days after the federal deadline for it had passed . Applying the month's updates is necessary and is not by itself an answer to what a given month left out.
