This website uses cookies

Read our Privacy policy and Terms of use for more information.

Patch Tuesday August 2026: 1 Zero-Day, 109 Critical Fixes Among 790 CVEs

Microsoft's August 2026 security update addresses 790 vulnerabilities: 109 rated Critical, 396 Important. 1 is already exploited in the wild and 2 were publicly disclosed before today.

This month's headline is a single actively exploited zero-day: CVE-2026-68820, a use-after-free EoP in the Windows Ancillary Function Driver for WinSock, already confirmed in KEV. It's the one CVE in this 790-fix batch you cannot leave for next week. Beyond that, the release is heavy on volume — 109 critical and 111 RCE fixes — but light on other confirmed exploitation, with two publicly disclosed EoP/tampering bugs in User Profile Service and the Container Isolation FS Filter Driver rounding out the disclosed-but-not-yet-exploited list.

Patch these first

  • CVE-2026-68820 (Important, CVSS 7.0) — Windows Ancillary Function Driver for WinSock: Elevation of Privilege — exploited in the wild, CISA KEV

CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0): a use-after-free that lets an already-authenticated local attacker elevate privileges to SYSTEM. It's marked exploited in the wild and is in KEV, so treat it as your top priority patch this cycle regardless of platform — AFD.sys underpins core networking on every supported Windows version, meaning any endpoint or server where a low-priv user or process can execute code is a viable target for local privilege escalation chains. Patch this today.

Publicly disclosed

  • CVE-2026-62832 (Important, CVSS 7.8) — Windows User Profile Service: Elevation of Privilege — publicly disclosed

  • CVE-2026-72971 (Important, CVSS 5.5) — Windows Container Isolation FS Filter Driver (unionfs.sys): Tampering — publicly disclosed

Also notable

  • CVE-2026-65665 (Critical, CVSS 8.8) — Microsoft Office SharePoint: Remote Code Execution

  • CVE-2026-63520 (Important, CVSS 8.1) — Microsoft Office SharePoint: Remote Code Execution

  • CVE-2026-59124 (Important, CVSS 9.8) — Microsoft High Performance Computing (HPC) Pack: Remote Code Execution

  • CVE-2026-62893 (Critical, CVSS 9.8) — Windows Deployment Services: Remote Code Execution

  • CVE-2026-59133 (Important, CVSS 8.8) — Microsoft High Performance Computing (HPC) Pack: Elevation of Privilege

  • CVE-2026-62823 (Critical, CVSS 8.8) — Windows DHCP Server: Remote Code Execution

  • CVE-2026-56162 (Critical, CVSS 10.0) — Azure SQL Database: Elevation of Privilege

  • CVE-2026-50481 (Critical, CVSS 9.9) — Azure Active Directory: Elevation of Privilege

By the numbers

  • Unspecified: 369

  • Elevation of Privilege: 176

  • Remote Code Execution: 111

  • Information Disclosure: 86

  • Spoofing: 21

  • Denial of Service: 12

  • Security Feature Bypass: 11

  • Tampering: 4

Subscribe free → I write a curated cybersecurity news roundup, including this breakdown each Patch Tuesday. Get it in your inbox.

Reply

Avatar

or to participate