Microsoft Patch Tuesday – August 2026
Today is Microsoft Patch Tuesday for August 2026. There are 400 vulnerabilities that have been addressed this time around. This is an unusually large release, with 42 of the flaws rated Critical and three zero-days – one of them already exploited in the wild by North Korean threat actors, and two publicly disclosed before a patch was available. The bulk of the release is elevation of privilege (176) and remote code execution (110), followed by information disclosure (86), spoofing (21), denial of service (12) and security feature bypass (11). Beyond the zero-days, the standouts are a wormable Windows DNS Server RCE and an Exchange Server authentication bypass that can hand over every mailbox on the server.
Notable Patch Tuesday vulnerabilities for August
CVE–2026–68820
Use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys), CVSS 7.0. A locally authenticated attacker can run a crafted application to trigger a race condition and elevate to SYSTEM without any user interaction. This is the actively exploited zero-day of the month: Check Point observed the Lazarus group abusing it to load a new version of their FudModule kernel-mode rootkit. Patch this one first on anything that could see a foothold.
Stack-based buffer overflow in Windows DNS Server, CVSS 9.8, remotely exploitable by an unauthenticated attacker with no user interaction – and considered wormable. Three more critical DNS Server RCEs shipped alongside it (CVE-2026-62817, CVE-2026-62820 and CVE-2026-65789), all remote and unauthenticated. Internet-facing or internally shared DNS servers should be at the top of the deployment queue.
Critical authentication bypass via capture-replay in Microsoft Exchange Server, originally demonstrated at Pwn2Own Berlin. A low-privileged attacker on the network can elevate privileges and take over the mailboxes of all Exchange users, allowing them to read mail, pull down attachments and send messages as trusted identities. No known exploitation yet, but the impact on an on-premises Exchange environment is about as bad as it gets.
Link-following flaw in the Windows User Profile Service, CVSS 7.8, publicly disclosed before the patch landed. An authenticated local attacker can abuse improper link resolution to reach another user’s registry hive and gain administrator privileges. This matches the previously published “LegacyHive” vulnerability.
The second publicly disclosed zero-day, a link-following tampering issue in the Windows Container Isolation FS Filter Driver (unionfs.sys), CVSS 5.5. Same pattern as the one above: an authenticated attacker manipulates another user’s registry hive to reach administrative privileges.
Critical remote code execution in the Remote Desktop Client, CVSS 8.8, requiring neither authentication nor user interaction. Worth noting because it hits the client side – a malicious or compromised RDP server can execute code on the machines connecting to it.
Also worth a look this month: a large batch of critical Microsoft Office RCEs, several of which are reachable through the Preview Pane, and two Windows GDI+ issues (CVE-2026-62822, CVSS 8.8 RCE and CVE-2026-62890, CVSS 7.8 EoP).
Note that the 400 count covers this month’s release only – fixes shipped earlier for Azure, Mariner, Teams, Office and Power Apps are counted separately, so other trackers may quote a slightly different number.
For more detailed information on these and other vulnerabilities, please refer to the release notes: : https://msrc.microsoft.com/updateguide/releaseNote/2026-Aug
Need help addressing the above in your own organization? Speak to an Outpost24 expert.