UpdateStar Vulnerability Index · August 2026

Monthly severity snapshot for widely-installed consumer software

70
Overall Score

SEVERE

August 2026 saw Microsoft ship its second-largest Patch Tuesday of the year — roughly 421 CVEs — including a fix for a Windows kernel-driver zero-day (AFD.sys) that North Korea's Lazarus group had been exploiting since early July in attacks on defense and aerospace targets. WinRAR's 2025 path-traversal flaw is now in its 13th month of active nation-state abuse. Chrome and Firefox both shipped large batches of critical and high-severity fixes with no confirmed in-the-wild attacks — but a low-severity 7-Zip Mark-of-the-Web bypass remains unpatched with no fix available at all.

2 × KEV Listed APT Active (Lazarus) 1 × Unpatched ~421 MS CVEs

Top 5 — Consumer App Severity

#1
Microsoft Windows (AFD.sys) CVE-2026-68820
Use-after-free in the Ancillary Function Driver for WinSock (AFD.sys), the kernel driver behind the Windows sockets API · present on every Windows endpoint · exploited by Lazarus since early July 2026 in "Operation Dream Job" attacks on defense and aerospace targets
CISA KEV Exploited ITW (Lazarus) Patched Aug 11
7.0
CVSS HIGH
#2
WinRAR CVE-2025-8088
Path traversal → Startup folder · Exploitation remains widespread and ongoing (RomCom, Turla, Gamaredon/APT44-linked activity, a PRC-linked actor, UNC4895) · No auto-update, ~500M users exposed
CISA KEV APT Active Patched 7.13
8.4
CVSS HIGH
#3
Google Chrome CVE-2026-76034 / -76036
A WebGL out-of-bounds write and a Dawn (WebGPU) flaw, both rated Critical by Google · could allow code execution outside the sandbox via a crafted page · no confirmed in-the-wild exploitation
Patched 151.0.7922.169/.170
Critical
CVSS PENDING (NVD)
#4
RAR5 alternate-data-stream name collision erases the Mark-of-the-Web on extraction, defeating SmartScreen/Internet-zone warnings · flagged as Empirical Security's "CVE of the Month," with exploitation telemetry as recently as Jul 25 · still unpatched in the current release (26.02), no auto-update
Unpatched — No Fix Available
4.8
CVSS MEDIUM
#5
Mozilla Firefox MFSA 2026-74
58 CVEs fixed in Firefox 154, including a sandbox escape in the Remote Settings Client and several internally-found bugs Mozilla says showed evidence of memory corruption and were presumed exploitable with effort · no confirmed in-the-wild exploitation, auto-update reliable
Patched Firefox 154
High
MOZILLA IMPACT

CVSS Score Comparison

Windows (AFD.sys) 7.0
WinRAR 8.4
Chrome Critical (pending)
Firefox High
7-Zip 4.8

Key Stats — August 2026

~421
Microsoft CVEs patched in a single Patch Tuesday (2nd-largest of 2026)
1
MS zero-day exploited ITW & added to CISA KEV (Windows AFD.sys)
58
CVEs fixed in a single Firefox release (154)
13+
Months WinRAR CVE-2025-8088 under continuous nation-state exploitation
−7
Days mean time-to-exploit (Mandiant M-Trends 2026)
43
Days median KEV remediation time (Verizon DBIR 2026)

Patch Lag — Days Since Disclosure vs. Update Status

WinRAR (CVE-2025-8088) 390+ d
Patched Jul 2025 · still under active nation-state exploitation 13+ months later, no auto-update
7-Zip (CVE-2026-58052) 55+ d
Disclosed Jun 28 · still unpatched as of version 26.02 · exploitation telemetry observed as recently as Jul 25
Windows (AFD.sys) (CVE-2026-68820) ~40 d
Exploited by Lazarus from early July; patched Aug 11 and added to CISA KEV the same day
Chrome (CVE-2026-76034 / -76036) <7 d
Fixed Aug 20 · no confirmed ITW exploitation
Firefox (MFSA 2026-74) <7 d
Fixed Aug 18 · auto-update reliable
Data sources: NVD · CISA KEV · Mandiant M-Trends 2026 · Verizon DBIR 2026 · vendor advisories (Microsoft MSRC, Mozilla, Google, RARLAB, 7-Zip/SourceForge, Empirical Security)
Check and update all software at updatestar.com · Download the UpdateStar Client for Windows

August 2026 Highlights

  • KEV2 CVEs on CISA Known Exploited Vulnerabilities list (1 new — Windows AFD.sys, 1 carryover — WinRAR)
  • APTLazarus exploiting a fresh Windows kernel zero-day; RomCom, Turla, Gamaredon and a PRC-linked actor continue abusing WinRAR
  • FIX7-Zip's Mark-of-the-Web bypass has no fix available even in the latest release
  • MS~421 Microsoft CVEs in a single Patch Tuesday — the 2nd-largest batch of 2026

Overall Severity Score

Index Score 70 / 100
Rating SEVERE

App Quick Reference

  • HIGH WinRAR 8.4
  • HIGH Windows (AFD.sys) 7.0
  • CRIT Chrome Critical*
  • HIGH Firefox High*
  • MED 7-Zip 4.8

Patch Status

  • Windows — patched Aug 11 (KB5121003/KB5120249); KEV-listed
  • WinRAR — patched but no auto-update, still actively exploited
  • Chrome — patched (151.0.7922.169/.170); no confirmed ITW
  • 7-Zip — not yet patched, no auto-update
  • Firefox — patched (154, auto-update); no confirmed ITW

Data Sources

  • NVD (National Vulnerability Database)
  • CISA Known Exploited Vulnerabilities
  • Mandiant M-Trends 2026
  • Verizon DBIR 2026
  • Vendor security advisories
Morty Proxy This is a proxified and sanitized view of the page, visit original site.