CVE-2026-68820: The Patch Is Out, the Timeline Isn't

Microsoft's August 12 Patch Tuesday disclosed CVE-2026-68820, a Windows driver vulnerability North Korean actors were already exploiting to deploy rootkits. The advisory says the flaw was being used in the wild. It does not say when Microsoft learned about the exploitation, how long attackers had access before the patch shipped, or whether affected organizations were notified before the public disclosure.

CVE-2026-68820 is a use-after-free bug in a Windows driver that grants SYSTEM-level access with no authentication required. Attackers don't need to be local. They don't need credentials. The vulnerability gives them kernel access from a remote starting position, which is exactly what you need to install a rootkit that security software can't see and logs can't be trusted to record.

The campaign is Operation Dream Job – North Korean state-sponsored social engineering that's been running for years. Fake LinkedIn recruiters contact targets with fake job offers. The interview process eventually requires the target to "review this document" or "install this collaboration software." The payload drops, CVE-2026-68820 escalates it to SYSTEM, and the rootkit goes in. At that point the attacker owns the machine at a level most defensive tools can't reach.

Microsoft's advisory was published August 12, 2026. That's when organizations running vulnerable Windows systems learned the flaw existed and that it was being actively exploited. Some of those organizations may have already been compromised and didn't know it yet, because rootkits at SYSTEM hide themselves. Others may have been targeted after the disclosure, once the technical details became public and the exploit code started circulating.

The timeline that matters is the one Microsoft isn't publishing: when they first learned CVE-2026-68820 was being exploited in the wild, how long it took to develop and test the patch, and whether they gave advance notice to organizations in sectors North Korean actors are known to target. Federal agencies get advance notice through CISA. Critical infrastructure sometimes gets a heads-up. Most organizations find out when the Patch Tuesday advisory goes live, which means they're learning about the vulnerability at the same time as everyone else – including attackers who didn't already have it.

The August 2026 Patch Tuesday also fixed two wormable RCEs, one in DNS and one in QUIC. Wormable means the flaw can spread without user interaction. DNS and QUIC are network protocols, which means a wormable RCE in either one is an internet-scale problem if someone weaponizes it. Microsoft hasn't said whether those two were being exploited. That usually means no, but it also means the technical details are now public and the clock is running.

CVE-2026-68820 is patched. If you're running Windows, you patch it now, not next maintenance window. But the question Microsoft's advisory doesn't answer is how many systems were compromised in the window between when North Korean actors started exploiting the flaw and when the patch went live. Rootkits don't announce themselves. The organizations that were hit may not know it yet, and when they do find out, the exfiltration will have already happened.

August 12 is when the patch shipped. The exploitation started before that. Microsoft knows when. They're not saying.