VYPR
patchPublished Aug 12, 2026· 1 source

Microsoft August Patch Tuesday Fixes Exploited Zero-Day, Over 400 Vulnerabilities

Microsoft's August 2026 Patch Tuesday addresses 400+ vulnerabilities, including an actively exploited zero-day in AFD.sys and three publicly disclosed flaws.

Microsoft's August 2026 Patch Tuesday has rolled out with fixes for over 400 vulnerabilities, prominently featuring CVE-2026-68820, a zero-day flaw that has already seen exploitation in the wild. This critical update aims to close numerous security gaps across its product ecosystem, with a particular focus on vulnerabilities that pose immediate threats.

The most pressing issue addressed is CVE-2026-68820, a use-after-free vulnerability residing in the Windows Ancillary Function Driver for WinSock (AFD.sys). This flaw allows a local attacker, even with low privileges, to escalate their access to SYSTEM level. Microsoft notes that exploitation requires a specially crafted application to trigger a race condition, and importantly, user interaction is not necessary. Researchers from Check Point have linked the exploitation of this vulnerability to North Korean threat actors, specifically within the 'Operation Dream Job' campaign, where it was used to deploy a kernel-mode rootkit.

In addition to the zero-day, Microsoft's August release tackles three other vulnerabilities that were publicly disclosed before patches were available. CVE-2026-62832, affecting the Windows User Profile Service, could allow an authenticated attacker to gain administrative privileges. This vulnerability is associated with 'LegacyHive,' a proof-of-concept exploit released by researcher Nightmare-Eclipse. It enables a standard user to manipulate the User Profile Service into loading another user's registry hive, thereby granting unauthorized access to administrator data.

Another publicly disclosed vulnerability, CVE-2026-72971, impacts the Windows Container Isolation FS Filter Driver (unionfs.sys). This flaw may permit authenticated attackers to tamper with vulnerable systems, though it is specifically noted to affect only Windows 11 versions for ARM64-based Systems. Crowdstrike also flagged CVE-2026-62737, an elevation of privilege vulnerability in the Windows kernel. While not officially acknowledged by Microsoft as publicly disclosed, a Chinese-language blog post on August 9, 2026, detailed a proof-of-concept exploit capable of causing a system crash.

Beyond these headline issues, the August Patch Tuesday addresses several other significant vulnerabilities. CVE-2026-62815, a critical flaw in Microsoft QUIC, allows unauthenticated attackers to execute code remotely by sending a specially crafted network packet. Similarly, CVE-2026-62878, a stack-based buffer overflow in Windows DNS, also presents an easily exploitable remote code execution risk for unauthenticated attackers. Furthermore, CVE-2026-63520, found in Microsoft SharePoint by Rapid7 researchers, can be chained with a previously patched SharePoint flaw (CVE-2026-55040) to achieve unauthenticated remote code execution.

In a related development, the security researcher known as 'Nightmare Eclipse' has released a proof-of-concept exploit named 'ShieldBreak.' This exploit reportedly bypasses the patch for CVE-2026-50656, a Microsoft Defender vulnerability dubbed 'RoguePlanet,' which was addressed in July's Patch Tuesday. The ShieldBreak PoC is said to affect Windows 11, 10, and Windows Server 2025, and has been confirmed to work if Microsoft Defender is enabled.

Security experts advise caution regarding the sheer volume of patches. While the number of vulnerabilities fixed is substantial, the rate of actively exploited zero-days has not seen a proportional increase, according to Dustin Childs of TrendAI's Zero Day Initiative. Organizations are urged to prioritize patching based on risk, considering factors like CVSS scores, exploitation status, and system exposure, rather than rushing all updates. Ivanti's Chris Goettl emphasizes the need for independent risk triage, especially when Microsoft may categorize actively exploited bugs as 'Unproven.'

Ultimately, IT administrators and security teams are advised to maintain a calm and methodical approach to patching. Tyler Reguly of Fortra recommends ensuring that rolled-out updates are stable and do not negatively impact systems. CISOs should engage with their teams to adapt patching workflows to accommodate this increased patching cadence and provide the necessary support for implementing these changes.

Synthesized by Vypr AI