Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-Days

Microsoft’s August 2026 Patch Tuesday addresses 400 vulnerabilities, including one actively exploited zero-day and two publicly disclosed zero-days. The release contains 42 critical vulnerabilities, with 37 classified as remote code execution flaws and five as elevation of privilege issues.

Although the total falls below July’s record 570 vulnerabilities, August remains an unusually large Patch Tuesday release. Microsoft has attributed the recent growth in security updates in part to its increased use of AI-assisted vulnerability discovery across its software.


Breakdown of Vulnerabilities

  • 176 Elevation of Privilege vulnerabilities
  • 110 Remote Code Execution vulnerabilities
  • 86 Information Disclosure vulnerabilities
  • 21 Spoofing vulnerabilities
  • 12 Denial of Service vulnerabilities
  • 11 Security Feature Bypass vulnerabilities

These totals exclude vulnerabilities addressed earlier in Mariner, Microsoft Teams, Azure, Microsoft Entra, Microsoft Office, and Power Apps.


Zero-Day Vulnerabilities

August’s Patch Tuesday addresses three zero-day vulnerabilities. One was actively exploited in attacks, while two had been publicly disclosed.

CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

This actively exploited use-after-free vulnerability allows a locally authenticated attacker to execute a specially crafted application, trigger a race condition, and gain SYSTEM privileges without additional user interaction.

Check Point attributed exploitation of CVE-2026-68820 to the North Korean Lazarus threat group. According to its investigation, attackers exploited the vulnerability to deploy a new version of FudModule, a kernel-mode rootkit associated with Lazarus operations. The vulnerability was discovered by Moshe Marelus and David Driker of Check Point.

CVE-2026-62832 | Windows User Profile Service Elevation of Privilege Vulnerability

This publicly disclosed vulnerability stems from improper link resolution before file access. An authenticated attacker with credentials for another local account can use a crafted application to load that user’s registry hive, potentially allowing access to or modification of another user’s data and elevation to administrator privileges.

The technical details align with the previously disclosed vulnerability known as LegacyHive. Microsoft officially attributes the discovery to an anonymous researcher.

CVE-2026-72971 | Windows Container Isolation FS Filter Driver Tampering Vulnerability

This publicly disclosed vulnerability involves improper link resolution in the Windows Container Isolation file system filter driver. Microsoft classifies the issue as a tampering vulnerability that can be exploited locally by an authorized attacker.

Microsoft has not released details about the original public disclosure and credits researchers yhw and txz with discovering the flaw.


Other Notable Vulnerabilities

Beyond the three zero-days, Microsoft addressed 39 other critical vulnerabilities this month. Remote code execution dominates the critical category, accounting for 37 of the 42 critical flaws in the August release.

The broader vulnerability distribution is also heavily concentrated around privilege escalation and code execution. August contains 176 elevation of privilege flaws and 110 RCE vulnerabilities, giving defenders a substantial patching workload even beyond the three zero-days.


Adobe and Other Vendor Updates

Several major vendors also released security updates during August 2026:

  • Adobe released security updates addressing vulnerabilities in ColdFusion, Commerce, Lightroom Classic, Content Credentials SDK, and Campaign Classic.
  • Cisco issued patches across numerous products, including Catalyst SD-WAN, IOS, IOS XE, and ClamAV vulnerabilities with publicly available exploit code.
  • Metabase patched a critical SQL injection vulnerability associated with data-theft attacks.
  • N-able addressed CVE-2026-18577, an authentication bypass vulnerability affecting hosted and on-premises N-central servers that has been exploited in attacks.
  • SAP released its August security updates, including a CVSS 10.0 improper authorization vulnerability affecting the SAP Commerce Cloud Data Hub Adapter.
  • TP-Link patched 15 vulnerabilities affecting the zero-touch provisioning mechanism used by Omada networking products, including flaws capable of leading to remote code execution.
  • VMware released security updates for Avi Load Balancer addressing authentication bypass and remote code execution vulnerabilities.

Recommendations for Users and Administrators

Organizations should prioritize CVE-2026-68820 due to confirmed exploitation and its ability to provide SYSTEM-level privileges. Endpoint detection teams should also review telemetry for suspicious AFD.sys activity and behaviors associated with post-exploitation privilege escalation, particularly given the reported use of the flaw by Lazarus to deploy a kernel-mode rootkit.

The two publicly disclosed vulnerabilities should also receive priority. Organizations should assess Windows User Profile Service exposure associated with CVE-2026-62832 and update affected systems to close the LegacyHive attack path. Windows container hosts should receive the fixes for CVE-2026-72971.

The large concentration of RCE and privilege escalation vulnerabilities warrants broader patching beyond the zero-days. Security teams should prioritize externally exposed services, identity infrastructure, privileged endpoints, servers, and systems where local access could be chained with one of the newly patched elevation flaws.

Third-party updates should be incorporated into the same patch cycle where applicable, particularly N-able N-central due to confirmed exploitation and Metabase due to reported data-theft activity. Cisco, SAP, TP-Link, Adobe, and VMware deployments should also be reviewed against their respective August advisories.

Full technical details and patch links are available in Microsoft’s Security Update Guide.


How Can Netizen Help?

Founded in 2013, Netizen is an award-winning technology firm that develops and leverages cutting-edge solutions to create a more secure, integrated, and automated digital environment for government, defense, and commercial clients worldwide. Our innovative solutions transform complex cybersecurity and technology challenges into strategic advantages by delivering mission-critical capabilities that safeguard and optimize clients’ digital infrastructure. One example of this is our popular “CISO-as-a-Service” offering that enables organizations of any size to access executive level cybersecurity expertise at a fraction of the cost of hiring internally. 

Netizen also operates a state-of-the-art 24x7x365 Security Operations Center (SOC) that delivers comprehensive cybersecurity monitoring solutions for defense, government, and commercial clients. Our service portfolio includes cybersecurity assessments and advisory, hosted SIEM and EDR/XDR solutions, software assurance, penetration testing, cybersecurity engineering, and compliance audit support. We specialize in serving organizations that operate within some of the world’s most highly sensitive and tightly regulated environments where unwavering security, strict compliance, technical excellence, and operational maturity are non-negotiable requirements. Our proven track record in these domains positions us as the premier trusted partner for organizations where technology reliability and security cannot be compromised.

Netizen holds ISO 27001, ISO 9001, ISO 20000-1, and CMMI Level III SVC registrations demonstrating the maturity of our operations. We are a proud Service-Disabled Veteran-Owned Small Business (SDVOSB) certified by U.S. Small Business Administration (SBA) that has been named multiple times to the Inc. 5000 and Vet 100 lists of the most successful and fastest-growing private companies in the nation. Netizen has also been named a national “Best Workplace” by Inc. Magazine, a multiple awardee of the U.S. Department of Labor HIRE Vets Platinum Medallion for veteran hiring and retention, the Lehigh Valley Business of the Year and Veteran-Owned Business of the Year, and the recipient of dozens of other awards and accolades for innovation, community support, working environment, and growth.

Looking for expert guidance to secure, automate, and streamline your IT infrastructure and operations? Start the conversation today.


Posted in , ,

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.