Microsoft August 2026 Patch Tuesday: 418 Vulnerabilities Addressed, Including Exploited Zero-Day
Microsoft's August 2026 Patch Tuesday addresses 418 vulnerabilities, featuring an actively exploited Windows privilege escalation flaw and two disclosed zero-days.

Microsoft's August 2026 Patch Tuesday has rolled out with a substantial update, patching a total of 418 vulnerabilities across its product lines. Among these, 62 are classified as critical, with one already being exploited in the wild and two others publicly disclosed as zero-days, underscoring the urgency for administrators to apply these security updates.
The most pressing issue highlighted is CVE-2026-68820, a Windows Ancillary Function Driver for WinSock use-after-free vulnerability. Rated as Important with a CVSS score of 7.0, this flaw allows a locally authenticated attacker with low privileges to gain SYSTEM privileges by running a specially crafted application that triggers a race condition. Microsoft has confirmed this vulnerability is being exploited in the wild, making it a priority for patching, especially on systems accessible to untrusted users.
Two zero-day vulnerabilities were also disclosed this month. The first, CVE-2026-62832, affects the Windows User Profile Service and is an improper link resolution issue. While not confirmed to be exploited in the wild, this Important-severity flaw (CVSS 7.8) could allow a local authenticated attacker to elevate privileges by manipulating user profile data. The second zero-day, CVE-2026-72971, impacts the Windows Container Isolation FS Filter Driver (unionfs.sys). Rated Important with a CVSS of 5.5, this vulnerability allows a local attacker to tamper with files, though Microsoft states it has not been exploited in the wild.
Beyond privilege escalation and tampering, Microsoft has also addressed critical remote code execution (RCE) vulnerabilities. CVE-2026-62815, a critical flaw in the Microsoft QUIC protocol, carries a CVSS score of 9.8. This use-after-free vulnerability could allow an unauthenticated remote attacker to execute code on the target system by sending a specially crafted network packet. Given its critical nature and potential for remote exploitation, patching systems exposed to untrusted networks is paramount.
Another critical RCE vulnerability, CVE-2026-62878, affects the Windows DNS Server. This stack-based buffer overflow flaw also has a CVSS score of 9.8 and can be triggered remotely by an unauthenticated attacker. Affected systems include a wide range of Windows Server releases, making prompt patching essential for network infrastructure security.
Administrators are advised to prioritize patching the actively exploited CVE-2026-68820, followed by the publicly disclosed zero-days (CVE-2026-62832 and CVE-2026-72971). Additionally, the critical RCE vulnerabilities in QUIC (CVE-2026-62815) and DNS Server (CVE-2026-62878) require immediate attention, particularly on internet-facing systems.
This month's Patch Tuesday highlights the ongoing challenges in securing complex software ecosystems. The combination of actively exploited vulnerabilities, zero-days, and critical RCE flaws underscores the need for robust patch management strategies and continuous monitoring for suspicious activity across Windows environments.
This August 2026 Patch Tuesday update from Microsoft addresses a total of 394 vulnerabilities, a slightly lower count than the 418 detailed in a previous report. Notably, this release includes fixes for three zero-day vulnerabilities: CVE-2026-68820, an actively exploited elevation of privilege in the Windows Ancillary Function Driver for WinSock; CVE-2026-72971, a publicly disclosed tampering vulnerability in the Windows Container Isolation driver; and CVE-2026-62832, another publicly disclosed elevation of privilege in the Windows User Profile Service. Additionally, a critical remote code execution vulnerability (CVE-2026-71331) affecting Azure Attestation services is also patched.
The new article provides additional detail on the exploited zero-day, identifying it as CVE-2026-68820, a use-after-free vulnerability in the afd.sys driver that allows for SYSTEM privilege escalation. It also highlights that this is the fourth afd.sys zero-day exploited since 2022, with previous instances linked to nation-state actors, including North Korea's Lazarus group.
This August 2026 Patch Tuesday from Microsoft addresses a total of 398 CVEs, an increase from the 418 vulnerabilities detailed in the previous month's update. While the total number of patched vulnerabilities is slightly lower, this month's release includes three zero-day vulnerabilities, one of which has been confirmed to be exploited in the wild, highlighting continued active threats.