Microsoft August 2026 Patch Tuesday Addresses 421 Vulnerabilities, Including Exploited SharePoint RCE and AFD EoP Flaws
Microsoft's August 2026 Patch Tuesday release tackles 421 vulnerabilities, with significant attention on a critical SharePoint RCE chain, an actively exploited Windows AFD EoP flaw, and other elevation of privilege and tampering issues.

Microsoft's August 2026 Patch Tuesday has arrived, bringing with it a substantial update addressing 421 vulnerabilities, 236 of which affect Windows. While this number is lower than the record-breaking totals seen in previous months, it still represents one of the largest Patch Tuesday releases in history, signaling a continued trend of high vulnerability disclosures.
The update includes several notable vulnerabilities, including CVE-2026-63520, a critical remote code execution (RCE) vulnerability in Microsoft SharePoint. Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer, this flaw is the second in a chain that, when combined with CVE-2026-55040, allows unauthenticated attackers to execute arbitrary code on vulnerable SharePoint servers. Patches are available for SharePoint Server Subscription Edition, 2019, and 2016.
Another significant disclosure is CVE-2026-68820, an elevation of privilege (EoP) vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). This vulnerability has been observed being exploited in the wild. While exploitation requires winning a race condition, making stable exploit development challenging, a successful attack grants SYSTEM-level access. Microsoft has assigned a CVSS v3 base score of 7.0 and a severity ranking of 'important,' though its in-the-wild exploitation status elevates its practical risk.
The Patch Tuesday also addresses CVE-2026-62832, an elevation of privilege vulnerability in the Windows User Profile Service. This flaw, disclosed publicly and described in detail by the pseudonymous researcher Nightmare Eclipse, allows an authenticated attacker with credentials for another account to gain administrator rights on the local system. This vulnerability is part of a series of disclosures by Nightmare Eclipse that have kept Microsoft busy.
Furthermore, CVE-2026-72971 is a tampering vulnerability affecting the Windows Container Isolation FS Filter Driver (unionfs.sys). Exploitation could allow an unauthorized attacker within a container to overwrite certain files, potentially leading to unauthorized impacts outside the container. Despite the potential for cross-container impact, Microsoft has classified it as having no scope change, with a low CVSS v3 base score of 5.5.
Notably, Microsoft appears to have released fewer browser security patches this month compared to previous Patch Tuesdays. While Chrome received updates on August 6th, Microsoft Edge, a downstream consumer of Google Chromium, had not received security patches for its desktop versions as of Patch Tuesday publication, with its last security update on July 31, 2026.
Microsoft is aware of active exploitation for CVE-2026-68820 and public disclosure for CVE-2026-63520 and CVE-2026-62832. While not yet on the CISA Known Exploited Vulnerabilities (KEV) catalog, CVE-2026-68820 is expected to be added soon. The sheer volume of vulnerabilities patched underscores the ongoing challenges in maintaining secure systems against a relentless tide of discovered flaws.