Microsoft Windows: 8 Flaws Including Privilege Escalation Disclosed Together in August 2026 Patch Tuesday
Microsoft's August 2026 Patch Tuesday addresses 8 Windows vulnerabilities, including high-severity flaws in Win32K and Schannel enabling local privilege escalation and information disclosure.

Key findings
- Three high-severity "use after free" vulnerabilities in Win32K and Schannel allow local privilege escalation.
- Information disclosure is a significant risk, with multiple CVEs enabling local data breaches.
- The batch includes a heap-based buffer overflow in LUAFV, also leading to local privilege escalation.
- All vulnerabilities were disclosed on the same day, August 11, 2026, indicating a coordinated patch release.
- The affected components span critical Windows services like Win32K, Schannel, COM, and Event Logging.
On August 11, 2026, Microsoft released its monthly security update, addressing a significant batch of 8 vulnerabilities affecting Windows. This disclosure includes several high-severity flaws, with a particular focus on privilege escalation and information disclosure. The vulnerabilities were disclosed on the same day, indicating a coordinated release by Microsoft to patch critical security gaps.
Several vulnerabilities stem from "use after free" flaws. CVE-2026-65775 and CVE-2026-62711, both affecting the Windows Win32K component, allow local attackers to elevate privileges. Similarly, CVE-2026-62779, a use after free vulnerability in Windows Schannel, also permits local privilege escalation. Another use after free vulnerability, CVE-2026-59136, impacts Microsoft COM for Windows and can lead to local information disclosure.
Beyond use after free issues, other vulnerabilities include a heap-based buffer overflow in Windows LUAFV (CVE-2026-50472), which allows for local privilege escalation with a CVSS score of 7.0. Information disclosure is also a concern, with CVE-2026-62743 (an out-of-bounds read in Win32K) and CVE-2026-61347 (a buffer over-read in the Windows Event Logging Service) both allowing local attackers to access sensitive data. Additionally, CVE-2026-62757, an improper verification of cryptographic signature in Windows Schannel, could allow an unauthorized attacker to bypass security features over a network.
Microsoft's August 2026 Patch Tuesday addressed a total of 421 vulnerabilities, with 62 marked as critical. While this batch focuses on local privilege escalation and information disclosure, other disclosed vulnerabilities include remote code execution flaws. Notably, Microsoft indicated that one vulnerability (CVE-2026-68820, not part of this specific batch) was being exploited in the wild, underscoring the urgency of applying security updates. Rapid7 Blog
The vulnerabilities detailed in this batch affect various components of the Windows operating system. Users are strongly advised to update their systems to the latest patched versions to mitigate the risks associated with these security flaws. Microsoft's Security Update Guide provides detailed information on each vulnerability and the specific patches released. Cyber Security News
This coordinated disclosure highlights the ongoing efforts by Microsoft to secure its operating system against a wide range of threats. The prevalence of privilege escalation and information disclosure vulnerabilities in this batch emphasizes the importance of timely patching to prevent local attackers from compromising system integrity and sensitive data. Users should prioritize applying these updates to maintain a secure computing environment.
Key findings from this batch include:
- Three high-severity "use after free" vulnerabilities in Win32K and Schannel allow local privilege escalation.
- Information disclosure is a significant risk, with multiple CVEs enabling local data breaches.
- The batch includes a heap-based buffer overflow in LUAFV, also leading to local privilege escalation.
- All vulnerabilities were disclosed on the same day, August 11, 2026, indicating a coordinated patch release.
- The affected components span critical Windows services like Win32K, Schannel, COM, and Event Logging.
The vulnerabilities disclosed on August 11, 2026, are: CVE-2026-65775, CVE-2026-62779, CVE-2026-62757, CVE-2026-62743, CVE-2026-62711, CVE-2026-61347, CVE-2026-59136, CVE-2026-50472. Links to advisories and further details can be found in the related news coverage. Cisco Talos Intelligence Zero Day Initiative