Microsoft Fixes Around 400 Flaws in August 2026 Patch Tuesday
Microsoft’s August 2026 Patch Tuesday fixes around 400 security vulnerabilities, including 42 Critical flaws and three zero-days affecting Windows.
Microsoft fixes around 400 vulnerabilities
Of the roughly 400 vulnerabilities addressed this month, 42 carry a Critical severity rating.
Microsoft classified 37 of those Critical flaws as remote code execution vulnerabilities, while five involve elevation of privilege.
The company also patched three zero-day vulnerabilities. Attackers had already exploited one of them in the wild.
Microsoft previously warned that its growing use of AI-powered security tools could result in more Windows security vulnerabilities being discovered and patched.
August Patch Tuesday vulnerability breakdown
Microsoft addressed vulnerabilities across several categories:
- 176 elevation of privilege vulnerabilities
- 110 remote code execution vulnerabilities
- 86 information disclosure vulnerabilities
- 21 spoofing vulnerabilities
- 12 denial-of-service vulnerabilities
- 11 security feature bypass vulnerabilities
These figures cover vulnerabilities Microsoft addressed as part of August 2026 Patch Tuesday. They do not include some security flaws patched earlier in the month across other Microsoft products.
Actively exploited Windows zero-day patched
One of the most important fixes addresses CVE-2026-68820, a vulnerability in the Windows Ancillary Function Driver for WinSock.
The use-after-free flaw allows a locally authenticated attacker to elevate privileges to SYSTEM.
An attacker must run a specially crafted application that triggers a race condition, although the attack does not require user interaction.
Microsoft has not shared additional details about how attackers exploited CVE-2026-68820 in real-world attacks.
Windows User Profile Service zero-day fixed
Microsoft also patched CVE-2026-62832, a publicly disclosed elevation of privilege vulnerability in the Windows User Profile Service.
The vulnerability appears to match the previously disclosed LegacyHive Windows zero-day.
An authenticated attacker who has credentials for another local account could load that user’s registry hive.
Successful exploitation could allow the attacker to access or modify another user’s data and potentially gain administrator privileges.
Windows Container Isolation flaw also patched
The third zero-day, CVE-2026-72971, affects the Windows Container Isolation FS Filter Driver, unionfs.sys.
Microsoft describes the issue as a publicly disclosed tampering vulnerability caused by improper link resolution.
A locally authenticated attacker can exploit the vulnerability.
New Windows 11 and Windows 10 updates are available
Microsoft released new cumulative Windows updates alongside the security fixes.
Windows 11 users received the KB5121003 and KB5120240 August 2026 cumulative updates.
Windows 10 users covered by Extended Security Updates received the KB5120249 August 2026 update.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages