Microsoft Patch Tuesday – August 2026

Today is Microsoft Patch Tuesday for August 2026. There are 400 vulnerabilities that have been addressed this time around. This is an unusually large release, with 42 of the flaws rated Critical and three zero-days – one of them already exploited in the wild by North Korean threat actors, and two publicly disclosed before a patch was available. The bulk of the release is elevation of privilege (176) and remote code execution (110), followed by information disclosure (86), spoofing (21), denial of service (12) and security feature bypass (11). Beyond the zero-days, the standouts are a wormable Windows DNS Server RCE and an Exchange Server authentication bypass that can hand over every mailbox on the server.

Notable Patch Tuesday vulnerabilities for August

CVE202668820

Use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys), CVSS 7.0. A locally authenticated attacker can run a crafted application to trigger a race condition and elevate to SYSTEM without any user interaction. This is the actively exploited zero-day of the month: Check Point observed the Lazarus group abusing it to load a new version of their FudModule kernel-mode rootkit. Patch this one first on anything that could see a foothold.

CVE202662878

Stack-based buffer overflow in Windows DNS Server, CVSS 9.8, remotely exploitable by an unauthenticated attacker with no user interaction – and considered wormable. Three more critical DNS Server RCEs shipped alongside it (CVE-2026-62817, CVE-2026-62820 and CVE-2026-65789), all remote and unauthenticated. Internet-facing or internally shared DNS servers should be at the top of the deployment queue.

CVE202662911

Critical authentication bypass via capture-replay in Microsoft Exchange Server, originally demonstrated at Pwn2Own Berlin. A low-privileged attacker on the network can elevate privileges and take over the mailboxes of all Exchange users, allowing them to read mail, pull down attachments and send messages as trusted identities. No known exploitation yet, but the impact on an on-premises Exchange environment is about as bad as it gets.

CVE202662832

Link-following flaw in the Windows User Profile Service, CVSS 7.8, publicly disclosed before the patch landed. An authenticated local attacker can abuse improper link resolution to reach another user’s registry hive and gain administrator privileges. This matches the previously published “LegacyHive” vulnerability.

CVE-2026-72971

The second publicly disclosed zero-day, a link-following tampering issue in the Windows Container Isolation FS Filter Driver (unionfs.sys), CVSS 5.5. Same pattern as the one above: an authenticated attacker manipulates another user’s registry hive to reach administrative privileges.

CVE202662824

Critical remote code execution in the Remote Desktop Client, CVSS 8.8, requiring neither authentication nor user interaction. Worth noting because it hits the client side – a malicious or compromised RDP server can execute code on the machines connecting to it.

Also worth a look this month: a large batch of critical Microsoft Office RCEs, several of which are reachable through the Preview Pane, and two Windows GDI+ issues (CVE-2026-62822, CVSS 8.8 RCE and CVE-2026-62890, CVSS 7.8 EoP).

Note that the 400 count covers this month’s release only – fixes shipped earlier for Azure, Mariner, Teams, Office and Power Apps are counted separately, so other trackers may quote a slightly different number.

For more detailed information on these and other vulnerabilities, please refer to the release notes: : https://msrc.microsoft.com/updateguide/releaseNote/2026-Aug

Need help addressing the above in your own organization? Speak to an Outpost24 expert.

About the Author

Marcus White Cybersecurity Specialist, Outpost24

Marcus is an Outpost24 cybersecurity specialist based in the UK, with 8+ years experience in the tech and cyber sectors. He writes about attack surface management, application security, threat intelligence, and compliance.