Microsoft has released its August 2026 Patch Tuesday updates, addressing more than 400 vulnerabilities across Windows, Office, Azure, Exchange, SharePoint, Developer Tools and other products.[6][10][14] Coverage from multiple vendors puts the total around 421 distinct CVEs and notes that at least one of the flaws is already being exploited as a zero-day, underscoring the urgency of this month’s patches.[6][14][15]
A breakdown published by SecurityWeek shows 236 vulnerabilities in Windows, 98 in Office, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, seven in Exchange Server, one in Defender and six across other products, highlighting the breadth of Microsoft’s attack surface.[6] Other analyses track roughly 60–70 discrete update packages tied to these issues, reflecting the complexity of deploying this Patch Tuesday across diverse enterprise environments.[1][5][8]
Among the most urgent fixes is CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock that has been exploited in the wild as a local elevation-of-privilege zero-day.[7][10][15] Microsoft also patched CVE-2026-62832 in the Windows User Profile Service, an elevation-of-privilege flaw that was publicly known prior to the update, and a cluster of remote code execution bugs in Windows DNS Server tracked as CVE-2026-62817, CVE-2026-62820, CVE-2026-62878 and CVE-2026-65789, all of which could be highly attractive to attackers targeting core infrastructure.[10][15] Critical cloud-side issues include Azure Entra ID spoofing (CVE-2026-62869), an Azure Logic Apps information disclosure bug (CVE-2026-56161) and a Microsoft 365 Admin Center elevation-of-privilege vulnerability (CVE-2026-62873), reinforcing that Microsoft’s SaaS and identity services are also in the line of fire.[7][15]
Development tooling features prominently in this release, with at least seven Visual Studio Code vulnerabilities documented by researchers, including security feature bypass issues such as CVE-2026-58650 and CVE-2026-69278 and additional bugs tied to GitHub Copilot integration.[7][12][15] These flaws raise the stakes for software supply chain security, since compromise of developer workstations or build environments can give adversaries a pathway to inject malicious code into downstream applications.[12][14]
Severity data compiled by Tenable and others indicates that roughly 40–80 vulnerabilities in the August drop are rated critical, depending on how overlapping components and bulletin families are counted, with hundreds more classified as important and a small number as moderate.[5][13][14] Several of the critical issues, including the Windows DNS Server bugs and certain .NET and Azure vulnerabilities, are remote code execution risks that could be weaponized for ransomware or intrusion campaigns if unpatched systems remain exposed to the internet.[1][10][15]
Defenders are being urged to prioritize systems exposed to the internet, domain controllers, productivity suites and developer workstations when deploying this month’s patches, with particular attention to assets where exploitation of CVE-2026-68820 could give attackers elevated local privileges as a stepping stone to lateral movement.[7][11][14] Guidance from security teams at Rapid7, RoboShadow and other vendors emphasizes rapid testing and rollout of the August updates, coupled with monitoring for signs of exploitation against the WinSock zero-day and newly fixed DNS and Azure flaws.[11][14][15]
SecurityWeek’s coverage characterizes this as one of the largest and most consequential Microsoft patch batches to date, reflecting the steady pace at which new weaknesses continue to be discovered across the company’s operating systems, cloud platforms and collaboration tools.[6] For enterprises, the message is clear: treating August’s Patch Tuesday as a high-priority maintenance window is essential to reducing exposure to active exploits and preparing for the inevitable surge in proof-of-concept code that typically follows major security update releases.[6][10][15]
References
- Microsoft Patch Tuesday August 2026: 751 CVEs Ranked by Risk
- August 2026 Microsoft Patch Tuesday | Tenable®
- Microsoft Fixes 421 CVEs, One Exploited Zero-Day – SecurityWeek
- Microsoft Patch Tuesday August 2026 – Priority Fixes – Hive Pro
- Microsoft Patch Tuesday, August 2026
- August 2026 Patch Tuesday: 421 CVEs & Zero-Days – Splashtop
- Patch Tuesday: August 2026 – RoboShadow
- August 2026 Patch Tuesday Analysis
- Microsoft Patch Tuesday – August 2026
- Patch Tuesday – August 2026 – Rapid7
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
