
August 11, 2026 02:08 PM 5 Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege. The approximate number of bugs in each vulnerability category is listed below: 176 Elevation of Privilege Vulnerabilities 11 Security Feature Bypass Vulnerabilities 110 Remote Code Execution Vulnerabilities 86 Information Disclosure Vulnerabilities 12 Denial of Service Vulnerabilities 21 Spoofing Vulnerabilities When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include some flaws in Mariner, Microsoft Teams, Microsoft Azure, Microsoft Entra, Microsoft Office, and Power Apps that were fixed by Microsoft earlier this month. While this Patch Tuesday is not as large as last month's, which fixed 570 flaws, it is still very large compared to the previous month. Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its software products. To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5121003 & KB5120240 cumulative updates and the Windows 10 KB5120249 extended security update. Microsoft patches 3 zero-days This month's Patch Tuesday fixes three zero-day vulnerabilities, with one exploited in attacks and two publicly disclosed. Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available. The actively exploited zero-day vulnerabilities addressed during this month's Patch Tuesday are: CVE-2026-68820 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in the Windows Ancillary Function Driver for WinSock that grants SYSTEM privileges. "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally," warns Microsoft. "A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required," continued Microsoft. The flaws were credited to Moshe Marelus and David Driker with Checkpoint. In a report released today, Check Point says the flaw was exploited in zero-day attacks by the North Korean threat actors known as Lazarus to deploy malware. "During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit," said Check Point. Microsoft has not shared any details on how the flaws were exploited. The two publicly disclosed zero-days that was fixed are: CVE-2026-62832 - Windows User Profile Service Elevation of Privilege Vulnerability Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges. "Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally," explains Microsoft. "An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required," continued Microsoft. While Microsoft attributed the flaw to an anonymous researcher, the details match a zero-day vulnerability called "LegacyHive" that was disclosed by a security researcher named Nightmare Eclipse last month. Tharros principal vulnerability analyst Will Dormann previously said that non-admin users can exploit LegacyHive to modify the registry hive to launch commands with administrative privileges when the when the admin account logs into a compromised device. CVE-2026-72971 - Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges. "Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally," explains Microsoft. "An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required," continued Microsoft. Microsoft has not shared any details on where the flaw was disclosed but attributed the discovery to yhw & txz. Recent updates from other companies Other vendors who released updates or advisories in August 2026 include: Adobe released security updates for vulnerabilities in Coldfusion, Commerce, Lightroom Classic, Content Credentials SDK, and Campaign Classic. Cisco released security updates for numerous products, including Cisco Catalyst SD-WAN, IOS, IOS XE, and ClamAV flaws with public exploits. Metabase released security updates for a critical SQLi flaw that was exploited in data-theft attacks. N-able released security updates for an actively exploited authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. SAP released the August security updates for numerous products, including a 10.0-severity improper authorization flaw in SAP Commerce Cloud (Data Hub Adapter). TP-Link patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could lead to RCE. VMware released security updates for VMware Avi Load Balancer, which include authentication bypasses and remote code execution flaws. The August 2026 Patch Tuesday Security Updates Below is the complete list of resolved vulnerabilities in the August 2026 Patch Tuesday updates, excluding flaws fixed before today. To access the full description of each vulnerability and the systems it affects, you can view the full report here. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Related Articles: Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days Microsoft releases Windows 10 KB5099539 extended security update Microsoft releases Windows 10 KB5120249 extended security update Check Point warns of SmartConsole zero-day exploited in attacks Windows 11 KB5101650 & KB5099414 cumulative updates released
Source: BleepingComputer
By Lawrence Abrams