VYPR
patchPublished Aug 12, 2026· 1 source

Microsoft August Patch Tuesday Addresses 421 Vulnerabilities, Including Exploited Zero-Days

Microsoft's August 2026 Patch Tuesday fixes 421 vulnerabilities, with a critical focus on three zero-days, including one exploited by the Lazarus Group.

Microsoft's August 2026 Patch Tuesday has arrived, bringing fixes for a substantial 421 vulnerabilities, 62 of which are classified as Critical. This batch, while smaller than July's record-breaking release, still represents a significant security update for Windows and other Microsoft products. Notably, the update addresses three zero-day vulnerabilities, including one that has been actively exploited in the wild by the notorious Lazarus Group to gain SYSTEM privileges.

Among the most pressing issues is CVE-2026-62893, a critical unauthenticated remote code execution (RCE) vulnerability affecting the TFTP server component of Windows Deployment Services (WDS). With a CVSS score of 9.8, this flaw could allow attackers to execute arbitrary code on affected servers, posing a significant risk in enterprise and educational network environments where WDS is commonly deployed. The lack of built-in authentication in TFTP makes this an attractive target for lateral movement.

Another significant fix is for CVE-2026-62832, a publicly disclosed elevation of privilege (EoP) vulnerability in the Windows User Profile Service, also known as LegacyHive. Researchers released a limited proof-of-concept (PoC) in July demonstrating how a local authenticated attacker could exploit the service's registry hive handling to load another user's hive, potentially gaining administrator privileges. The availability of this PoC, coupled with the widespread use of Windows, makes this vulnerability a prime candidate for exploitation attempts.

The Lazarus Group's exploitation of a separate zero-day for SYSTEM privileges highlights the ongoing threat landscape. While specific details about this vulnerability are not fully disclosed in this report, its active exploitation underscores the importance of applying these patches promptly to prevent further compromise. The group's consistent targeting of various sectors makes any actively exploited vulnerability a high-priority concern.

Beyond these critical zero-days, Microsoft has also patched a significant number of RCE vulnerabilities in its Office suite. The update includes fixes for 48 RCE flaws affecting applications such as Excel, Word, Outlook, PowerPoint, and the Office graphics component. Document-borne vulnerabilities remain a popular vector for phishing attacks, as malicious attachments and shared documents are often opened by unsuspecting users.

Users are strongly advised to apply these updates as soon as possible. The process is straightforward: navigate to Settings > Windows Update and click 'Check for updates.' Windows will automatically download and install available security patches. A system restart may be required to complete the installation. Promptly updating ensures that systems are protected against known exploits and newly discovered threats.

The August Patch Tuesday also includes fixes for a potentially wormable Windows DNS Server flaw and other elevation of privilege and tampering issues, further emphasizing the breadth of vulnerabilities addressed. The cumulative effect of these patches is crucial for maintaining a robust security posture against the ever-evolving threat landscape.

Synthesized by Vypr AI