DarkReading

Microsoft August 2026 Patch Tuesday Fixes 400 Flaws


Microsoft’s August 2026 Patch Tuesday release addresses roughly 400 security flaws across its products, including three Zero-days. One of the three is being actively exploited, while the other two were publicly disclosed before Microsoft issued fixes. 

The August 2026 Patch Tuesday update includes 42 vulnerabilities rated “Critical.” Of those, 37 involve remote code execution, and five involve elevation of privilege. The vulnerability breakdown is approximately 176 elevation-of-privilege flaws, 11 security-feature bypasses, 110 remote-code-execution flaws, 86 information-disclosure issues, 12 denial-of-service vulnerabilities, and 21 spoofing vulnerabilities. 

Although smaller than July’s 570-flaw release, the August 2026 Patch Tuesday remains unusually large. Microsoft has previously warned that security updates could increase as its AI-powered vulnerability discovery system identifies additional flaws across its software products. 

August 2026 Patch Tuesday Zero-days 

Microsoft defines a zero-day as a vulnerability that has been publicly disclosed or actively exploited before an official fix is available. The three Zero-days addressed in August 2026 are: 

CVE-2026-68820 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability: This actively exploited flaw allows a locally authenticated attacker to trigger a race condition through a specially crafted application and obtain SYSTEM privileges without user interaction. 

Microsoft credited Moshe Marelus and David Driker of Check Point. Check Point reported that North Korean Lazarus threat actors exploited the flaw in Zero-day attacks to deploy a new version of the FudModule kernel-mode rootkit. “During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit,” Check Point said. Microsoft has not disclosed exploitation details. 

CVE-2026-62832 — Windows User Profile Service Elevation of Privilege Vulnerability: This publicly disclosed flaw can allow an authenticated attacker with credentials for another local account to load another user’s registry hive, potentially access or modify data and gain administrator privileges. Microsoft credited an anonymous researcher. The details match the “LegacyHive” Zero-day disclosed last month by researcher Nightmare Eclipse. 

CVE-2026-72971 — Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability: This publicly disclosed flaw involves improper link resolution and allows authenticated attackers to perform local tampering. Microsoft attributed its discovery to yhw and txz but did not identify where the vulnerability was disclosed. 

August 2026 Security Updates 

Microsoft’s August 2026 release consists of 421 Microsoft CVEs spanning Azure, Defender, Developer Tools, Exchange Server, Office, Office 2016, Other, SharePoint Server and Windows. Windows accounts for 236 vulnerabilities, Office for 98, SharePoint Server for 30, Developer Tools for 26, Azure for 17, Exchange Server for seven, Other for six, and Defender for one. 

The release also republishes two non-Microsoft CVEs: CVE-2026-6726 and CVE-2026-6727, both tagged as Windows TPM issues by MITRE. FAQs are available for both, while no workarounds or mitigations are listed.  Separate non-security releases include Windows 11 KB5121003 and KB5120240 cumulative updates and the Windows 10 KB5120249 extended security update. 



Source link