Microsoft's August 2026 security update addresses 790 vulnerabilities: 109 rated Critical, 396 Important. 1 is already exploited in the wild and 2 were publicly disclosed before today.
This month's headline is a single actively exploited zero-day: CVE-2026-68820, a use-after-free EoP in the Windows Ancillary Function Driver for WinSock, already confirmed in KEV. It's the one CVE in this 790-fix batch you cannot leave for next week. Beyond that, the release is heavy on volume — 109 critical and 111 RCE fixes — but light on other confirmed exploitation, with two publicly disclosed EoP/tampering bugs in User Profile Service and the Container Isolation FS Filter Driver rounding out the disclosed-but-not-yet-exploited list.
Patch these first
- CVE-2026-68820 (Important, CVSS 7.0) — Windows Ancillary Function Driver for WinSock: Elevation of Privilege — exploited in the wild, CISA KEV
CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0): a use-after-free that lets an already-authenticated local attacker elevate privileges to SYSTEM. It's marked exploited in the wild and is in KEV, so treat it as your top priority patch this cycle regardless of platform — AFD.sys underpins core networking on every supported Windows version, meaning any endpoint or server where a low-priv user or process can execute code is a viable target for local privilege escalation chains. Patch this today.
Publicly disclosed
- CVE-2026-62832 (Important, CVSS 7.8) — Windows User Profile Service: Elevation of Privilege — publicly disclosed
- CVE-2026-72971 (Important, CVSS 5.5) — Windows Container Isolation FS Filter Driver (unionfs.sys): Tampering — publicly disclosed
Also notable
- CVE-2026-65665 (Critical, CVSS 8.8) — Microsoft Office SharePoint: Remote Code Execution
- CVE-2026-63520 (Important, CVSS 8.1) — Microsoft Office SharePoint: Remote Code Execution
- CVE-2026-59124 (Important, CVSS 9.8) — Microsoft High Performance Computing (HPC) Pack: Remote Code Execution
- CVE-2026-62893 (Critical, CVSS 9.8) — Windows Deployment Services: Remote Code Execution
- CVE-2026-59133 (Important, CVSS 8.8) — Microsoft High Performance Computing (HPC) Pack: Elevation of Privilege
- CVE-2026-62823 (Critical, CVSS 8.8) — Windows DHCP Server: Remote Code Execution
- CVE-2026-56162 (Critical, CVSS 10.0) — Azure SQL Database: Elevation of Privilege
- CVE-2026-50481 (Critical, CVSS 9.9) — Azure Active Directory: Elevation of Privilege
By the numbers
- Unspecified: 369
- Elevation of Privilege: 176
- Remote Code Execution: 111
- Information Disclosure: 86
- Spoofing: 21
- Denial of Service: 12
- Security Feature Bypass: 11
- Tampering: 4
Source: Microsoft Security Update Guide and the CISA KEV catalog.
Subscribe free → I write a curated cybersecurity news roundup, including this breakdown each Patch Tuesday. Get it in your inbox.
Top comments (0)