VYPR
patchPublished Aug 16, 2026· 1 source

Microsoft's August Patch Tuesday Tackles 394 Vulnerabilities, Including Exploited Zero-Days

Microsoft's August 2026 Patch Tuesday addressed a record 394 vulnerabilities, featuring three actively exploited or publicly disclosed zero-days impacting Windows Container Isolation, User Profile Service, and AFD.sys.

Microsoft's August 2026 Patch Tuesday update has rolled out with a staggering 394 vulnerability disclosures, setting a new record for the company's monthly security release. Among these, three zero-day vulnerabilities were highlighted due to active exploitation or public disclosure, demanding immediate attention from administrators.

The most critical of these is CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver (AFD.sys). This vulnerability was actively exploited by North Korea's Lazarus Group as part of a renewed 'Operation Dream Job' campaign. The group leveraged this zero-day to deploy an upgraded FudModule rootkit, targeting defense, aerospace, and aviation firms across Europe, India, and Brazil with sophisticated social engineering tactics.

Another significant disclosure is CVE-2026-72971, a tampering vulnerability in the Windows Container Isolation driver. This flaw was publicly disclosed, meaning exploit details are available, increasing the risk of widespread exploitation if not patched promptly. Alongside this, CVE-2026-62832, a privilege escalation vulnerability in the Windows User Profile Service, was also publicly disclosed, posing a risk to user data and system integrity.

Beyond the zero-days, the update addresses a broad spectrum of security issues across Windows, Office, Azure, .NET, and other Microsoft products. The 394 vulnerabilities include 150 elevation-of-privilege bugs, 132 remote code execution flaws, and 66 information-disclosure vulnerabilities. Notably, a Critical RCE in Azure Attestation/Device Health Attestation (CVE-2026-71331) and multiple vulnerabilities in SharePoint and PowerShell also require urgent patching.

The August Patch Tuesday also included fixes for a high-severity integer overflow flaw in Microsoft Outlook, CVE-2026-70329, which could allow remote code execution if a user opens a maliciously crafted file. While Microsoft initially rated exploitation as unlikely, the public availability of proof-of-concept code could change this assessment.

Furthermore, several vulnerabilities affecting Microsoft Exchange Server were patched, including CVE-2026-62911, an authentication-bypass-by-replay flaw demonstrated at Pwn2Own Berlin, which could allow attackers to read mailboxes and send emails. Another critical Exchange flaw, CVE-2026-62913, enables unauthenticated network RCE without user interaction.

Microsoft urges organizations to prioritize the patching of the three zero-day vulnerabilities and other Critical-rated bugs. While Click-to-Run installations of Office products update automatically, administrators of MSI-based deployments and on-premises Exchange servers must manually apply the necessary patches to mitigate these widespread risks.

This extensive patch release underscores the persistent threat landscape and Microsoft's ongoing efforts to address a vast number of vulnerabilities, particularly those actively targeted by sophisticated threat actors like Lazarus.

Synthesized by Vypr AI