Today is Microsoft’s August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
Patch Tuesday addresses 42 “Critical” vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege.
The approximate number of bugs in each vulnerability category is listed below:
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.
Therefore, the number of flaws does not include some flaws in Mariner, Microsoft Teams, Microsoft Azure, Microsoft Entra, Microsoft Office, and Power Apps that were fixed by Microsoft earlier this month.
While this Patch Tuesday is not as large as last month’s, which fixed 570 flaws, it is still very large compared to the previous month.
Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its software products.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5121003 & KB5120240 cumulative updates and the Windows 10 KB5120249 extended security update.
This month’s Patch Tuesday fixes three zero-day vulnerabilities, with one exploited in attacks and two publicly disclosed.
Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.
The actively exploited zero-day vulnerabilities addressed during this month’s Patch Tuesday are:
CVE-2026-68820 – Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft has patched an actively exploited vulnerability in the Windows Ancillary Function Driver for WinSock that grants SYSTEM privileges.
“Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally,” warns Microsoft.
“A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required,” continued Microsoft.
The flaws were credited to Moshe Marelus and David Driker with Checkpoint.
In a report released today, Check Point says the flaw was exploited in zero-day attacks by the North Korean threat actors known as Lazarus to deploy malware.
“During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit,” said Check Point.
Microsoft has not shared any details on how the flaws were exploited.
The two publicly disclosed zero-days that was fixed are:
CVE-2026-62832 – Windows User Profile Service Elevation of Privilege Vulnerability
Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges.
“Improper link resolution before file access (‘link following’) in Windows User Profile Service allows an authorized attacker to elevate privileges locally,” explains Microsoft.
“An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required,” continued Microsoft.
While Microsoft attributed the flaw to an anonymous researcher, the details match a zero-day vulnerability called “LegacyHive” that was disclosed by a security researcher named Nightmare Eclipse last month.
Tharros principal vulnerability analyst Will Dormann previously said that non-admin users can exploit LegacyHive to modify the registry hive to launch commands with administrative privileges when the when the admin account logs into a compromised device.
CVE-2026-72971 – Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges.
“Improper link resolution before file access (‘link following’) in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally,” explains Microsoft.
“An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required,” continued Microsoft.
Microsoft has not shared any details on where the flaw was disclosed but attributed the discovery to yhw & txz.
Other vendors who released updates or advisories in August 2026 include:
Below is the complete list of resolved vulnerabilities in the August 2026 Patch Tuesday updates, excluding flaws fixed before today.
To access the full description of each vulnerability and the systems it affects, you can view the full report here.
Today is Microsoft’s August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
Patch Tuesday addresses 42 “Critical” vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege.
The approximate number of bugs in each vulnerability category is listed below:
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.
Therefore, the number of flaws does not include some flaws in Mariner, Microsoft Teams, Microsoft Azure, Microsoft Entra, Microsoft Office, and Power Apps that were fixed by Microsoft earlier this month.
While this Patch Tuesday is not as large as last month’s, which fixed 570 flaws, it is still very large compared to the previous month.
Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its software products.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5121003 & KB5120240 cumulative updates and the Windows 10 KB5120249 extended security update.
This month’s Patch Tuesday fixes three zero-day vulnerabilities, with one exploited in attacks and two publicly disclosed.
Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.
The actively exploited zero-day vulnerabilities addressed during this month’s Patch Tuesday are:
CVE-2026-68820 – Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft has patched an actively exploited vulnerability in the Windows Ancillary Function Driver for WinSock that grants SYSTEM privileges.
“Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally,” warns Microsoft.
“A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required,” continued Microsoft.
The flaws were credited to Moshe Marelus and David Driker with Checkpoint.
In a report released today, Check Point says the flaw was exploited in zero-day attacks by the North Korean threat actors known as Lazarus to deploy malware.
“During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit,” said Check Point.
Microsoft has not shared any details on how the flaws were exploited.
The two publicly disclosed zero-days that was fixed are:
CVE-2026-62832 – Windows User Profile Service Elevation of Privilege Vulnerability
Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges.
“Improper link resolution before file access (‘link following’) in Windows User Profile Service allows an authorized attacker to elevate privileges locally,” explains Microsoft.
“An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required,” continued Microsoft.
While Microsoft attributed the flaw to an anonymous researcher, the details match a zero-day vulnerability called “LegacyHive” that was disclosed by a security researcher named Nightmare Eclipse last month.
Tharros principal vulnerability analyst Will Dormann previously said that non-admin users can exploit LegacyHive to modify the registry hive to launch commands with administrative privileges when the when the admin account logs into a compromised device.
CVE-2026-72971 – Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges.
“Improper link resolution before file access (‘link following’) in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally,” explains Microsoft.
“An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required,” continued Microsoft.
Microsoft has not shared any details on where the flaw was disclosed but attributed the discovery to yhw & txz.
Other vendors who released updates or advisories in August 2026 include:
Below is the complete list of resolved vulnerabilities in the August 2026 Patch Tuesday updates, excluding flaws fixed before today.
To access the full description of each vulnerability and the systems it affects, you can view the full report here.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft releases Windows 10 KB5120249 extended security update
Check Point warns of SmartConsole zero-day exploited in attacks
Windows 11 KB5101650 & KB5099414 cumulative updates released
I assume those 400 “flaws” have not even begun to include all the new possibilities that AI agents will come up with? I think the whole security “business” will have to come up with a completely new way of looking at security?
Many of the article links to MSFT are incorrect. The have ‘CVE-2026-50528’ embedded in the middle of the URL.
Many of these still link to CVE-2026-50528 for me. I’ve noticed these articles prioritize speed over accuracy. They always want to post it within an hour of the patch going live, and as a result, quality of the overall article suffers. The links seem to be updated after the stories have already been posted.
LexisNexis shuts down services after suspicious activity on servers
Valve notifies Steam hardware customers of a data breach
Critical Progress LoadMaster flaw now actively exploited in attacks
Webinar: Shadow AI in 2026 (and how attackers are taking advantage)
Overdue a password health-check? Audit your Active Directory for free
See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats
See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



