Summary
Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities, including 62 critical flaws and one actively exploited zero-day in the Windows Ancillary Function Driver. The update covers a most products from Azure and Office to Windows Server components like DNS and DHCP.
Take Action:
Patch the Windows OS first for the AFD.sys zero-day first, it is already being used by North Korean state actors to load a kernel rootkit. Then move through Office, Word, and Excel, followed by SharePoint Server and Exchange. Windows DNS and DHCP servers should be next, as they carry critical remotely reachable RCE flaws. Everything else can follow in the normal cycle.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)