CVE-2026-68820

Microsoft — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Patch Tuesday

What EVULNABLE says

EVULNABLE Risk · priority 75/100 Urgent Raised to the floor for a confirmed exploited vulnerability.
Patch TuesdayActively Exploited

Why it matters: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Patch This Cycle

The priority band answers “how soon”, not “how bad” — see Methodology for what it weighs and where it abstains.

The evidence behind it

Published measurements for CVE-2026-68820
MeasureValueSource
CVSS base score 7.0
FIRST EPSS 0.062 (93rd pctl) FIRST
Actively exploited Confirmed CISA KEV
Ransomware campaign use Unknown or none CISA KEV
CISA remediation deadline CISA KEV

This page is an opinion about urgency. Where it and a source of record disagree, the source of record is the record.