Microsoft issued its August 2026 security updates, addressing 421 vulnerabilities across its product ecosystem, according to security updates published by the company. The release features a high-severity, actively exploited zero-day vulnerability located in the Windows Ancillary Function Driver for WinSock, tracked as CVE-2026-68820, which threat actors have leveraged to gain system privileges in ongoing attacks.
Windows Kernel Zero-Day Exploited in the Wild
The zero-day flaw in the Ancillary Function Driver for WinSock (afd.sys) involves a use-after-free weakness triggered by a race condition, according to Microsoft. A locally authenticated attacker can run a specially crafted application to exploit the defect, achieving full SYSTEM-level execution without requiring user interaction, as detailed in Microsoft’s advisory.
Privilege Escalation and Remote Code Execution Vectors
In addition to the kernel driver zero-day, the August 2026 Patch Tuesday deployment addresses several other critical components. Microsoft highlighted CVE-2026-62832, an improper link resolution flaw within the User Profile Service that permits local attackers to load other users’ registry hives and secure administrator privileges, according to security advisory details. Zero Day Initiative researcher Dustin Childs noted that the security rollout also patches remote code execution bugs affecting Windows DNS servers, Microsoft QUIC, the Microsoft HPC Pack, and an elevation of vulnerability in Exchange Server, alongside a critical remote code execution flaw in Windows Deployment Services (WDS) TFTP Server tracked as CVE-2026-62893.

Comprehensive Patch Distribution Breakdown
The August 2026 security catalog spans multiple software categories to mitigate widespread attack surfaces. According to vulnerability distribution data reported by SecurityWeek, the total count of 421 resolved common vulnerabilities and exposures includes:
- Windows: 236 vulnerabilities
- Office and Office 2016: 196 vulnerabilities combined
- SharePoint Server: 30 vulnerabilities
- Developer Tools: 26 vulnerabilities
- Azure: 17 vulnerabilities
- Exchange Server: 7 vulnerabilities
- Defender and Other Products: 7 vulnerabilities
The patches additionally cover two non-Microsoft items, resolving a spoofing bug (CVE-2026-6726) and an information disclosure issue (CVE-2026-6727) in the TPM 2.0 reference implementation, according to the security release notes.
Worth a look