Microsoft’s August 2026 Patch Tuesday fixes 400 security flaws, including three zero-day
vulnerabilities: one already used in real attacks and two that were publicly disclosed before a fix. The
actively exploited flaw lets an attacker who is already on a Windows machine gain full SYSTEM control,
and it has been used by North Korean state hackers to install a stealthy kernel rootkit. With 42 flaws
rated critical, organisations should roll out the August updates quickly, starting with the actively
exploited issue.
1. Vulnerability Details
Microsoft’s August 2026 Patch Tuesday addresses 400 vulnerabilities, 42 of them rated Critical (37 remote code execution and 5 elevation of privilege). The largest categories are elevation of privilege (176), remote code execution (110), and information disclosure (86). Microsoft attributes the growing patch volume in part to its AI-powered vulnerability discovery system and expects future releases to stay large. Three of the fixes are zero-days: one exploited in the wild and two publicly disclosed before a patch was available.
- CVE-2026-68820: Windows AFD.sys (WinSock) Elevation of Privilege, ACTIVELY EXPLOITED A use-after-free race condition in the Windows Ancillary Function Driver for WinSock lets a locally authenticated attacker gain SYSTEM privileges with no user interaction. Check Point reports the North Korean actor Lazarus exploited it as a zero-day to deploy a new version of the FudModule kernel rootkit.
- CVE-2026-62832: Windows User Profile Service Elevation of Privilege, PUBLICLY DISCLOSED An improper link resolution (link-following) flaw lets an authenticated attacker who holds credentials for another local account load that user’s registry hive and reach administrator privileges. The details match the LegacyHive zero-day disclosed publicly by researcher Nightmare Eclipse.
- CVE-2026-72971: Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering, PUBLICLY
- DISCLOSED An improper link resolution flaw in unionfs.sys lets an authenticated attacker perform local tampering, accessing or modifying another user’s data. Microsoft attributes the discovery to researchers yhw and txz.
2. Other Notable Fixes
Beyond the three zero-days, several of the 42 critical bugs are worth prioritising, and other vendors shipped fixes the same day.
- Critical network RCEs: Critical remote code execution flaws were fixed in Windows DNS Server (CVE-2026-62817), Routing and Remote Access / RRAS (CVE-2026-62819), Secure Socket Tunneling Protocol / SSTP (CVE-2026-62889), Deployment Services (CVE-2026-62893), and DHCP Server (CVE-2026-62823). Prioritise these on exposed and internal servers.
- Client and Office RCEs: Critical remote code execution flaws were also fixed in Microsoft Office (CVE-2026-63515), Word (CVE-2026-64907), SharePoint Server (CVE-2026-65665), GDI+ (CVE-2026-62822), and the Remote Desktop Client (CVE-2026-62824), which are typically triggered by malicious documents or connections.
- AI-driven patch volume: Microsoft says its AI-powered vulnerability discovery system is a major reason for the large release and expects Patch Tuesday volumes to keep rising.
- Same-day third-party fixes: Other vendors patched actively exploited flaws the same day, including N-able N-central (CVE-2026-18577), Metabase (SQL injection), and Cisco ClamAV, alongside Adobe, SAP, TP-Link, and VMware.
3. Recommendations
- Apply the August 2026 cumulative updates fleet-wide, prioritising the actively exploited AFD.sys flaw CVE2026-68820, which grants SYSTEM privileges.
- Prioritise the two publicly disclosed elevation-of-privilege zero-days, CVE-2026-62832 (User Profile Service) and CVE-2026-72971 (unionfs.sys), since public disclosure raises exploitation likelihood.
- Patch the critical, network-reachable remote code execution flaws first on internet-facing and internal servers Windows DNS Server, RRAS, SSTP, Deployment Services, and DHCP Server.
- Patch client-side remote code execution flaws in Microsoft Office, Word, SharePoint, and the Remote Desktop Client, which are typically triggered by malicious documents or connections.
4. Sources
- https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-4
- 00-flaws-3-zero-days/
- https://www.zerodayinitiative.com/blog/2026/8/11/the-august-2026-security-update-review
- https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/
- https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-68820
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.