A long list of CVEs doesn’t mean much to leadership on its own. What matters is exploitation, exposure, and business criticality — together.
Microsoft’s August 2026 Patch Tuesday covered 415 vulnerabilities, 62 of them rated Critical. But the one that should be getting immediate attention isn’t the highest-scoring one. CVE-2026-68820 is a Windows privilege-escalation bug rated CVSS 7.0, and Microsoft has confirmed it’s already being exploited. An attacker with a local foothold can use it to get SYSTEM privileges.
A 9.8 on a system you don’t operate can create zero real exposure. A 7.0 being actively exploited on a system running a critical business process is a different conversation entirely.
CVE-2026-68820 sits in the Windows Ancillary Function Driver for WinSock. CrowdStrike notes that a low-privileged attacker can use it to escalate straight to SYSTEM, and that Microsoft has confirmed in-the-wild exploitation. The Hacker News later linked Lazarus Group to attacks exploiting the flaw against defense and aerospace targets in France, Germany, Brazil, and India — deploying malware including ForestTiger and a newly identified backdoor called Troy.
So the question security teams should be bringing to non-security leadership isn’t “we’re rolling out August’s patches.” It’s: where do vulnerable systems sit, which critical processes depend on them, and do we actually have evidence exploitation hasn’t already happened?
Same logic applies to VMware. The Hacker News reports active exploitation of CVE-2026-59310, a 9.8 directory-traversal flaw in VMware vCenter. In at least one investigated compromise, attackers dropped a backdoor with reverse SSH access, then followed up with Babuk-derived ransomware — which researchers think may have been deployed partly to muddy the forensic trail, not just for the payout.
vCenter underpins large chunks of virtual infrastructure at most organizations. So the vulnerability needs to be weighed against whatever business services actually depend on that infrastructure — not treated as a standalone score.
And not every critical exposure starts with a CVE. France’s Directorate General of Public Finances disclosed a breach affecting roughly 678,000 people. The agency says attackers got in using compromised credentials — one belonging to an employee, one to a third-party account — and pulled tax and property data.
That incident points at a familiar list:
compromised employee identities
vendor and third-party accounts
excessive privileges
stale external access
stolen sessions or credentials
weak monitoring of trusted access
None of this is new. New CVEs, new breach headlines — the details change, the categories don’t. The actual job for security teams is translating these into questions leadership can act on:
Is this interrupting revenue?
Is it touching customers?
Does it expose regulated or sensitive data?
Does it hand over privileged access to other systems?
Does it compromise recovery infrastructure?
Will it require customer, regulatory, or board communication?
This is how we will make vulnerability management become CYBER-RESILIENCE.
Sources
CrowdStrike, August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs, 11 August 2026.
SecurityWeek, 680,000 Impacted by French Tax Authority Data Breach, 17 August 2026.
The Hacker News, Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More, 17 August 2026.