CVE-2026-62832Active Exploitation(microsoft / windows_10_21h2)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_21h2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_21h2
  • windows_10_22h2
  • windows_11_23h2
  • windows_11_24h2

Threat summary

  • Active exploitation appears in 12 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 21 mentions across 9 observed days

What's happening

  • Active exploitation reported across 12 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 16 signals
  • Disclosure: 3 classified signals
  • Peaked 6d ago at 6 mentions (2026-08-13); latest day: 1
  • 21 total mentions across 9 days

Affected systems

Vendors
Products
windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2022windows_server_2025

Deep dive

Activity timeline21 mentions / 9d
02356Mentions · 2026-08-11: 3Mentions · 2026-08-12: 1Mentions · 2026-08-13: 6Mentions · 2026-08-14: 3Mentions · 2026-08-15: 1Mentions · 2026-08-17: 3Mentions · 2026-08-18: 1Mentions · 2026-08-20: 2Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-17: 2Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-08-11: 3Active Exploitation · 2026-08-12: 1Active Exploitation · 2026-08-13: 3Active Exploitation · 2026-08-14: 2Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-08-18: 1Active Exploitation · 2026-08-20: 1Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-13: 5Patch / Workaround · 2026-08-14: 2Patch / Workaround · 2026-08-17: 2Patch / Workaround · 2026-08-20: 2Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-11: 2Technical Details · 2026-08-12: 1Technical Details · 2026-08-13: 5Technical Details · 2026-08-14: 3Technical Details · 2026-08-15: 1Technical Details · 2026-08-17: 2Technical Details · 2026-08-18: 1Technical Details · 2026-08-20: 108-1108-1208-1308-1408-1508-1708-1808-2008-26
Signal classification5 categories
Active Exploitation
1047.6%
Patch
628.6%
Disclosure
314.3%
General
14.8%
PoC
14.8%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-08-113
Active Exploitation3
2026-08-121
Active Exploitation1
2026-08-136
Active Exploitation2Disclosure1Patch3
2026-08-143
Active Exploitation2Patch1
2026-08-151
Disclosure1
2026-08-173
Disclosure1General1PoC1
2026-08-181
Active Exploitation1
2026-08-202
Active Exploitation1Patch1
2026-08-261
Patch1
Full discourse20 posts
  • CloudSecurityAlliance@cloudsa
    PoC

    CISO Daily Briefing: Chrome DevTools hijack defeats Google's Device-Bound Session Credentials. Windows CVE-2026-62832 privesc has public PoC pre-patch, inside MSFT's second 400-flaw AI-scale Patch Tuesday — patch capacity is now a standing risk. Jewelbug/XG-Web runs state espionage + crypto fraud off one panel, 580K+ cookies stolen. Gov: ~42% of cyber policies now carry AI exclusions; insurers rolling out AI Security Riders. https://labs.cloudsecurityalliance.org/research/alt-ciso-briefing-2026-08-17/

    Post summary

    The briefing details a Windows privilege‑escalation CVE with a publicly available PoC before patch, underscoring the importance of timely patching amid AI policy changes.

    01031552
    18.9K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝘂𝗴𝘂𝘀𝘁 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 August Patch Tuesday is here, and we have 𝟯 𝗻𝗲𝘄 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀 and 𝟲 vulnerabilities with a CVSS score of 9.0+. 𝗭𝗲𝗿𝗼-𝗗𝗮𝘆𝘀 🔸 CVE-2026-68820 – Windows Ancillary Function Driver for WinSock Elevation of Privilege 🔸 CVE-2026-72971 – Windows Container Isolation FS Filter Driver Tampering 🔸 CVE-2026-62832 – Windows User Profile Service Elevation of Privilege Of those, 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟲𝟴𝟴𝟮𝟬 is already being exploited in the wild and can lead to SYSTEM privileges. And among the 9.0+ vulnerabilities, we have multiple unauthenticated network RCEs, including Windows DNS Server, Windows Deployment Services TFTP Server, and Windows iSCSI Target Service. Full breakdown coming in this month’s Horizon Alert. #PatchTuesday #CyberSecurity #ZeroDay #Vulnerability #Microsoft

    Post summary

    The Horizon Alert highlights nine high‑severity vulnerabilities, noting that CVE-2026-68820 is currently being exploited in the wild for SYSTEM privilege escalation, while also listing multiple zero‑day and RCE issues.

    00041392
    2.7K followersView on X
  • Titis Tech Guide@titistechguide
    Patch

    Microsoft baru aja patch zero-day "LegacyHive" di Windows User Profile Service. Attacker bisa dapet akses admin tanpa perlu interaksi korban meski butuh kredensial tambahan biar bisa dieksploitasi. Udah dipatch di Patch Tuesday Agustus 2026 (CVE-2026-62832). Update sekarang! #Windows #Microsoft #CyberSecurity #ZeroDay #PatchTuesday #InfoSec #LegacyHive #TechNews

    Post summary

    Microsoft released a patch for the LegacyHive zero‑day affecting Windows User Profile Service, enabling administrators to gain control without user interaction.

    00020181
    5.1K followersView on X
  • tec4net@tec4net
    Active Exploitation

    Nordkoreanische Hacker greifen Windows-Systeme in Europa an Microsoft hat mit den August-Updates 421 Sicherheitslücken geschlossen. Eine davon, CVE-2026-68820, wird bereits von der nordkoreanischen Hackergruppe Lazarus für Angriffe genutzt. Betroffen sind unter anderem Organisationen aus dem Verteidigungssektor in Europa und Indien. Anwender sollten die Sicherheitsupdates daher zeitnah installieren. Die Schwachstelle steckt in einem Zusatztreiber für Winsock (AFD.sys) und ermöglicht nach erfolgreicher Ausnutzung weitreichende Rechte bis auf Kernelebene. Lazarus nutzt sie im Rahmen der Kampagne „Operation Dream Job“, bei der Opfer mit attraktiven Jobangeboten angesprochen werden. Über die Lücke wird eine neue Version des Rootkits Fudmodule eingeschleust. Microsoft hat zudem weitere gefährliche Windows-Lücken geschlossen. Dazu gehört CVE-2026-62832, für die bereits ein öffentlicher Exploit verfügbar ist. Kritisch sind auch Schwachstellen in Windows-DNS-Servern, den Windows Deployment Services und der Implementierung des Quic-Protokolls. Teilweise sind weder vorherige Authentifizierung noch Nutzerinteraktion erforderlich. Von den 421 behobenen Schwachstellen betreffen 236 allein Windows. Weitere Lücken finden sich in Office, SharePoint Server, Entwicklertools und Azure-Diensten. Die hohe Zahl unterstreicht die Bedeutung eines konsequenten Patch- und Sicherheitsmanagements. Quelle: https://www.golem.de/news/auch-in-europa-nordkoreanische-hacker-attackieren-windows-nutzer-2608-211834.html Audit und Beratung zu ISO 27001, TISAX und NIS2 https://www.tec4net.com/web/it-security/ Wir sind Experten für Datenschutz und IT-Sicherheit Profitieren Sie von unserer umfassenden Beratung zu den Themen Datenschutz und IT-Sicherheit. Unser erfahrenes Team unterstützt Sie dabei, Ihre Website und digitalen Dienste datenschutzkonform zu gestalten um die gesetzlichen Vorgaben zu erfüllen. Kontaktieren Sie uns noch heute und sichern Sie sich praxisnahe Beratung zur Umsetzung der DSGVO und Normen wie ISO 27001, PCI-DSS oder TISAX. Datenschutz und IT-Sicherheit praktikabel umsetzen – tec4net GmbH http://www.tec4net.com – http://www.it-news-blog.com – http://www.it-sachverstand.info – http://www.datenschutz-muenchen.com – http://www.it-sicherheit-muenchen.com Alle unsere NEWS -> http://news.tec4net.com

    Post summary

    The article reports that the Lazarus group is actively exploiting CVE‑2026‑68820 in Europe and India, while Microsoft has issued patches; it also notes a public exploit exists for CVE‑2026‑62832.

    0002093
    64 followersView on X
  • Machina Record@MachinaRecord
    Active Exploitation

    🚨VMware vCenterのRCE脆弱性を攻撃者が悪用: CVE-2026-59310 ⚠️Nightmare Eclipse、Windowsのゼロデイエクスプロイト「ShieldBreak」をリリース 🩹マイクロソフト、Nightmare EclipseがリリースしたWindowsゼロデイ「LegacyHive」を修正(CVE-2026-62832) 〜サイバーアラート8月14日〜 https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/47172/

    Post summary

    The alert reports attackers exploiting a VMware vCenter RCE (CVE‑2026‑59310) and notes the release of Windows zero‑day exploits ShieldBreak and LegacyHive (CVE‑2026‑62832), the latter of which Microsoft has patched.

    01010204
    1.3K followersView on X
  • Action1@Action1corp
    Active Exploitation

    Still sorting through Patch Tuesday? A few vulnerabilities deserve a closer look. In his August Patch Tuesday coverage for Infosecurity Magazine, Phil Muncaster looks at some of the vulnerabilities that stood out this month. Mike Walters highlights CVE-2026-68820 as a priority for organizations. It’s already being exploited in the wild and could give attackers elevated privileges and broad control over a Windows system. Jack Bicer also looks at two publicly disclosed vulnerabilities: CVE-2026-62832, which could expose another user’s data and lead to admin privileges, and CVE-2026-72971, a Windows Container Isolation flaw tied to improper file access handling. If you’re still working through August’s patching priorities, this is worth a read. https://hubs.ly/Q04tqLwT0 #PatchTuesday #Patching #Action1

    Post summary

    The post reports that CVE-2026-68820 is actively exploited in the wild, granting elevated privileges on Windows, while also outlining other significant but less imminent CVEs.

    00010103
    618 followersView on X
  • Samit Hota @HotaSamit
    Patch

    Microsoft Patches LegacyHive Windows Zero-Day Vulnerability CVE-2026-62832 Microsoft has patched CVE-2026-62832, a Windows User Profile Service zero-day known as LegacyHive that allowed… Full write-up → link in bio #cybersecurity #infosec #VulnerabilityDisclosure #microsoft https://t.co/9hkZ4oAz2z

    Post summary

    The tweet announces that Microsoft has released a patch for the CVE-2026‑62832 Windows User Profile Service zero‑day (LegacyHive). It contains no evidence of active exploitation, PoC, or exploit code.

    0000199
    20 followersView on X
  • Human Firewall@HumanFirewallHQ
    Disclosure

    Two more zero-days were public before yesterday: CVE-2026-62832 — User Profile Service link-following, a.k.a. "LegacyHive". Microsoft rates exploitation MORE LIKELY. Local creds → another user's hive → admin. CVE-2026-72971 — unionfs.sys container filter (less likely).

    Post summary

    Two newly disclosed zero-day vulnerabilities (CVE-2026-62832 and CVE-2026-72971) are announced, with brief technical details but no PoC, exploit code, or evidence of active exploitation.

    1000058
    2 followersView on X
  • Tako@tac0tech
    Active Exploitation

    Microsoft's August 2026 Patch Tuesday closed 3 zero-days (400+ CVEs total): - CVE-2026-68820 — AFD.sys (WinSock) — actively exploited - CVE-2026-62832 — Windows User Profile Service — publicly disclosed - CVE-2026-72971 — Container Isolation FS Filter Driver — publicly disclosed

    Post summary

    Microsoft’s August 2026 Patch Tuesday fixed three zero‑day vulnerabilities; one (CVE-2026-68820 in AFD.sys) was actively exploited and all were addressed by the patch.

    0001089
    5 followersView on X
  • kawn@kawn2020
    Active Exploitation

    #windowsupdate #microsoft ■重要 CVE ID/タイトル/重要な項目 ・CVE-2026-62832 Windows User Profile Service の特権の昇格の脆弱性 一般的に知られている ・CVE-2026-68820 WinSock 用 Windows Ancillary Function Driver の特権の昇格の脆弱性 悪用の事実を確認済み https://x.com/kawn2020/status/2087361247994159533

    Post summary

    The tweet confirms that CVE-2026-68820 is actively exploited in the wild, while CVE-2026-62832 is generally known; no PoC, exploit code, patch, or false‑positive claims are provided.

    1000095
    90 followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    Microsoft's August Patch Tuesday fixed 400 flaws, including 3 Windows zero-days, all local privilege-escalation bugs needing no user interaction: • CVE-2026-68820: AFD.sys WinSock flaw, already exploited by Lazarus to deploy the FudModule rootkit • CVE-2026-62832: User Profile Service flaw ('LegacyHive'), publicly disclosed • CVE-2026-72971: Container Isolation filter driver flaw, publicly disclosed 42 of the 400 fixes are rated Critical. Patch now.

    Post summary

    Microsoft’s August Patch Tuesday addressed 400 issues, including the actively exploited CVE‑2026‑68820, and all listed CVEs have vendor patches available.

    00010104
    599 followersView on X
  • PatronusCyber@PatronusCyber
    Patch

    Microsoft has patched LegacyHive, now tracked as CVE-2026-62832, after the Windows vulnerability was publicly disclosed before an official fix was available. The patch is available. Now it needs to reach affected systems. #CyberSecurity #WindowsSecurity https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/

    Post summary

    Microsoft has released a patch for the LegacyHive vulnerability (CVE-2026-62832), but the update still needs to reach affected systems.

    00000126
    5 followersView on X
  • SharkStriker@TheSharkStriker
    General

    Microsoft addresses the LegacyHive flaw in Windows (CVE-2026-62832) - SharkStriker https://sharkstriker.com/blog/microsoft-addresses-legacyhive-flaw-in-windows-cve-2026-62832/ . . #microsoft #legacyhive #windowsflaw

    Post summary

    A blog post announces that Microsoft has addressed the LegacyHive flaw (CVE‑2026‑62832) in Windows, but offers no further technical or patch details.

    0000025
    120 followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    Microsoft'un Ağustos Yaması Final Raporunda 421 Açık ve İki Ek Sıfır Gün Ortaya Çıktı Daha önce duyurduğumuz Microsoft Ağustos yamasının resmi final raporunda toplam açık sayısı 398'den 421'e yükseldi ve Lazarus'un istismar ettiği CVE-2026-68820'nin yanında iki yeni sıfır gün açığı daha ortaya çıktı! • "LegacyHive" olarak adlandırılan CVE-2026-62832, kullanıcı profil hizmetinde; CVE-2026-72971 ise konteyner sürücüsünde yetki yükseltmesine yol açıyor. • Ayrıca CVSS 9.8'lik dört kritik uzaktan kod yürütme açığı ve Exchange'de kimlik doğrulamayı atlatmaya izin veren CVE-2026-62911 de bu ayki yamada kapatıldı. Bir Patch Tuesday raporunun ilk yayınlanmasından günler sonra bile açık sayısının ve sıfır gün listesinin güncellenmeye devam etmesi, bu ölçekteki güvenlik güncellemelerinin tam kapsamının ortaya çıkmasının zaman alabildiğini gösteriyor. #SiberGüvenlik #Microsoft #PatchTuesday

    Post summary

    The final report of Microsoft’s August Patch identifies 421 total vulnerabilities, introduces two new zero-days—including a Lazarus‑exploited CVE‑2026‑68820—and confirms that all are addressed in the current update.

    0000053
    39 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - Windows User Profile Service EoP via Link Following (CVE-2026-62832) Windows User Profile Service improperly resolves reparse points/symlinks before file access during profile operations, letting an authenticated local user redirect writes to a protected path. This link-following flaw can be abused to overwrite privileged files and elevate to SYSTEM. 👉Affected: Microsoft Windows (User Profile Service)

    Post summary

    The post announces a new Windows User Profile Service vulnerability (CVE‑2026‑62832) that allows an authenticated local user to exploit link following for privilege escalation to SYSTEM.

    0000091
    289 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers are exploiting CVE-2026-62832 to modify registry hives and escalate privileges on Windows systems. The LegacyHive vulnerability enables lateral movement through compromised administrator accounts. Runtime segmentation can help limit blast radius when internal pivoting occurs. #ZeroDay #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/legacyhive-windows-zero-day-privilege-escalation-2026

    Post summary

    Attackers are actively exploiting CVE-2026-62832 to modify registry hives, elevate privileges, and perform lateral movement using compromised administrator accounts.

    0000061
    1.9K followersView on X
  • Undercode News@undercode_news
    Patch

    🚨 #Microsoft Finally Patches the LegacyHive #Windows Zero-Day, #CVE-2026-62832, After Weeks of Exposure + Video -Fact Checker: ✅: 2 ❌: 1 || 2/3 → Score: 66% ⚖️ -Prediction: 📈 0 Positive | 📉 1 Negative https://undercodenews.com/microsoft-finally-patches-the-legacyhive-windows-zero-day-cve-2026-62832-after-weeks-of-exposure-video/

    Post summary

    Microsoft has issued a patch for the Windows LegacyHive zero‑day CVE‑2026‑62832 after the vulnerability was reportedly exploited for weeks.

    0000074
    75 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    Microsoft patched the LegacyHive Windows zero-day, CVE-2026-62832, in August 2026 updates. The flaw in Windows User Profile Service could let authenticated local attackers gain admin privileges. #LegacyHive #CVE202662832 #WindowsUpdate https://www.hendryadrian.com/microsoft-patches-legacyhive-windows-zero-day-vulnerability/ https://t.co/wZwBLpF9zR

    Post summary

    Microsoft released a patch in August 2026 for CVE‑2026‑62832, a Windows User Profile Service vulnerability that could let authenticated local users elevate privileges to admin.

    00000281
    4.6K followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Microsoft has patched the LegacyHive Windows zero-day (CVE-2026-62832), a flaw in the User Profile Service that allowed local privilege escalation. Disclosed by researcher Nightmare Eclipse, the exploit required extra credentials but still posed serious risk. Patch now live in August 2026 updates.

    Post summary

    Microsoft has released a patch in the August 2026 updates for CVE-2026-62832, a local privilege escalation vulnerability in the User Profile Service.

    0000085
    38 followersView on X
  • aratech@aratech_social
    Active Exploitation

    Microsoft just dropped 421 patches. One is already exploited in the wild. CVE-2026-68820: SYSTEM-level privilege escalation via Windows kernel driver afd.sys CVE-2026-62832: any local user can grab admin rights Your 48-hour patch checklist: https://aratech.ae/blog/microsoft-august-patch-tuesday-2026 #PatchTuesday #CyberSecurity

    Post summary

    Microsoft released 421 patches, among which CVE-2026-68820 (privilege escalation via afd.sys) and CVE-2026-62832 (local admin elevation) are highlighted; at least one is actively exploited in the wild and a patch checklist is provided.

    0000076
    109 followersView on X
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2025---

Explore more