International Edition
Latest News
Technology

Microsoft August 2026 Patch Tuesday Fixes 421 CVEs and Zero-Day Flaw

Microsoft issued its August 2026 security updates, addressing 421 vulnerabilities across its product ecosystem, according to security updates published by the company. The release features a high-severity, actively exploited zero-day vulnerability located in the Windows Ancillary Function Driver…

Microsoft issued its August 2026 security updates, addressing 421 vulnerabilities across its product ecosystem, according to security updates published by the company. The release features a high-severity, actively exploited zero-day vulnerability located in the Windows Ancillary Function Driver for WinSock, tracked as CVE-2026-68820, which threat actors have leveraged to gain system privileges in ongoing attacks.

Windows Kernel Zero-Day Exploited in the Wild

The zero-day flaw in the Ancillary Function Driver for WinSock (afd.sys) involves a use-after-free weakness triggered by a race condition, according to Microsoft. A locally authenticated attacker can run a specially crafted application to exploit the defect, achieving full SYSTEM-level execution without requiring user interaction, as detailed in Microsoft’s advisory.

Privilege Escalation and Remote Code Execution Vectors

In addition to the kernel driver zero-day, the August 2026 Patch Tuesday deployment addresses several other critical components. Microsoft highlighted CVE-2026-62832, an improper link resolution flaw within the User Profile Service that permits local attackers to load other users’ registry hives and secure administrator privileges, according to security advisory details. Zero Day Initiative researcher Dustin Childs noted that the security rollout also patches remote code execution bugs affecting Windows DNS servers, Microsoft QUIC, the Microsoft HPC Pack, and an elevation of vulnerability in Exchange Server, alongside a critical remote code execution flaw in Windows Deployment Services (WDS) TFTP Server tracked as CVE-2026-62893.

421 bugs in Microsoft
Photo: imtr.net

Comprehensive Patch Distribution Breakdown

The August 2026 security catalog spans multiple software categories to mitigate widespread attack surfaces. According to vulnerability distribution data reported by SecurityWeek, the total count of 421 resolved common vulnerabilities and exposures includes:

From Instagram — related to microsoft august 2026 patch, Exchange Server
  • Windows: 236 vulnerabilities
  • Office and Office 2016: 196 vulnerabilities combined
  • SharePoint Server: 30 vulnerabilities
  • Developer Tools: 26 vulnerabilities
  • Azure: 17 vulnerabilities
  • Exchange Server: 7 vulnerabilities
  • Defender and Other Products: 7 vulnerabilities

The patches additionally cover two non-Microsoft items, resolving a spoofing bug (CVE-2026-6726) and an information disclosure issue (CVE-2026-6727) in the TPM 2.0 reference implementation, according to the security release notes.

SANS Stormcast Wednesday, August 12th, 2026: Microsoft Patch Tuesday; Zoom Vulnerabilities; Moz…

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”