Back to Blog
CVE-2026-68820: Microsoft Windows — Lazarus Gains System Control (June 2026)
vulnerabilities

CVE-2026-68820: Microsoft Windows — Lazarus Gains System Control (June 2026)

breachwire TeamAug 25, 20262 min read

CVE-2026-68820 — Microsoft Windows

CVE-2026-68820 is a high-severity Windows zero-day vulnerability allowing remote attackers to achieve System-level code execution. The flaw is actively exploited by North Korean Lazarus Group, with confirmed use in targeted attacks since early 2026. No CVSS score is published, but exploitation is confirmed in the wild. CVE-2025-49113 is also referenced in related activity.

Attack Vector

Attackers use spear-phishing emails with fake job offers to deliver trojanized documents and malware, exploiting CVE-2026-68820 to execute code with System privileges. Post-exploitation, adversaries deploy the ForestTiger and Troy backdoors for persistent access, and leverage RelayShell PHP webshells on compromised Roundcube webmail and CMS platforms. SecurityPDF, a trojanized PDF viewer, is also used for initial access or lateral movement. The campaign enables reconnaissance, persistence, and data exfiltration.

Who Is at Risk

Targets include Windows systems in aerospace, aviation, and defense organizations across Europe, India, Brazil, and other regions. Any enterprise using unpatched Windows endpoints or vulnerable Roundcube/CMS platforms is at risk. No specific organizations are named, but defense sector entities are confirmed targets.

Patch & Mitigate

  • Patch: Apply the latest Microsoft security update addressing CVE-2026-68820 immediately. Confirm patch deployment on all endpoints.
  • Workaround: None documented. Isolate unpatched systems from sensitive networks.
  • Detect: Monitor for RelayShell PHP webshell activity, ForestTiger/Troy backdoor signatures, and anomalous access to Roundcube or CMS platforms. Review logs for suspicious PDF viewer launches and privilege escalation events.

MITRE ATT&CK

  • TA0001 — Initial Access: Spear-phishing with malicious attachments delivers malware to targets.
  • TA0005 — Defense Evasion: Use of webshells and backdoors to maintain undetected persistence.
  • TA0008 — Lateral Movement: Deployment of secondary backdoors and exploitation of internal platforms for deeper access.

Source: https://www.securityweek.com/fresh-windows-zero-day-exploited-in-north-korean-cyberattacks/

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: