TL;DR
Microsoft August 2026 Patch Tuesday fixes 421 vulnerabilities, with 62 rated critical. One flaw, CVE-2026-68820, is already exploited in the wild. Microsoft also patched two other zero-days that researchers publicly disclosed before a fix shipped.
- Product: Microsoft (3 products)
- Vulnerabilities: 3 flaws (CVE-2026-68820, CVE-2026-62832, CVE-2026-72971)
- Highest severity: 7.8 (High · CVSSv3)
- Worst impact: Windows User Profile Service Elevation of Privilege
- Status: 1 exploited; patches available
- Action: Update to 10.0.14393.9418, 10.0.17763.9115, 10.0.19044.7663, 10.0.19045.7663 (+8) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-62832 | 7.8 | CWE-59 | 10.0.19044.7663, 10.0.19045.7663, 10.0.22631.7517 (+5) | Not exploited |
| CVE-2026-68820 | 7 | CWE-416 | 10.0.14393.9418, 10.0.17763.9115, 10.0.19044.7663 (+9) | Exploited |
| CVE-2026-72971 | 5.5 | CWE-59 | 10.0.28000.2704 | Not exploited |
Why This Patch Tuesday Matters
Microsoft shipped an unusually large update this month. The count reached 421 CVEs, including 62 critical bugs. Most notably, attackers exploited one zero-day before the patch arrived.
The exploited flaw stands out most. Multiple vendors, including Checkpoint, confirmed active abuse of CVE-2026-68820. Security teams should treat it as an emergency fix.
How the Attack Works
CVE-2026-68820 is a use-after-free bug in the Ancillary Function Driver for WinSock, or afd.sys. That kernel driver underpins the Windows Sockets API.
A local, low-privileged attacker runs a crafted application to trigger a race condition. As a result, they escalate to SYSTEM privileges. Researchers link the attacks to North Korea’s Lazarus Group, which used the flaw to deploy its FudModule rootkit.
The Two Publicly Disclosed Zero-Days
Two more zero-days were publicly disclosed before this Patch Tuesday. CVE-2026-62832 is an elevation of privilege flaw in the Windows User Profile Service. CVE-2026-72971 is a link-following bug in the Container Isolation driver. Microsoft has not confirmed exploitation of either one.
Affected Products
This month’s fixes span Windows, Office, Exchange Server, SharePoint, and Azure. Other notable RCE bugs affect the Windows DNS Server, Microsoft QUIC, and Deployment Services. The WinSock zero-day affects supported Windows client and server versions.
Patch and Mitigation Steps
Deploy this month’s updates now, starting with the exploited WinSock flaw. Windows 11 users should install the latest cumulative update. You can confirm each fix through the official Microsoft Security Update Guide.
Prioritize the actively exploited bug first. Then patch the two publicly disclosed zero-days and the remaining critical CVEs across your fleet.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.