400 Vulnerabilities Fixed, Including Three Zero-Days
Microsoft has released its August 2026 Patch Tuesday security updates, addressing 400 vulnerabilities across its ecosystem, including 42 Critical vulnerabilities and three zero-days.
One of those zero-days was already being actively exploited in the wild before a patch was available.
For security teams, the headline number is significant. But 400 vulnerabilities also creates a familiar problem: where do you start?
Not every vulnerability presents the same level of risk to every organisation. Understanding what is exposed, what is being actively exploited and which vulnerabilities could have the greatest impact is critical to turning another huge Patch Tuesday into a manageable remediation plan.
What Has Microsoft Fixed?
Microsoft's August security updates address hundreds of vulnerabilities across Windows and other products.
According to reporting on the release, the vulnerabilities include approximately:
- 176 Elevation of Privilege vulnerabilities
- 110 Remote Code Execution vulnerabilities
- 86 Information Disclosure vulnerabilities
- 21 Spoofing vulnerabilities
- 12 Denial of Service vulnerabilities
- 11 Security Feature Bypass vulnerabilities
Of the vulnerabilities addressed, 42 are rated Critical, including 37 remote code execution vulnerabilities and five elevation of privilege vulnerabilities.
The volume follows Microsoft's warning that organisations could see larger Patch Tuesday releases as it increases its use of AI-powered vulnerability discovery to identify security weaknesses across its products.
For IT and security teams, that could mean an increasingly important shift from simply identifying vulnerabilities to being able to prioritise and remediate them efficiently.
Three Zero-Days Fixed
Three zero-day vulnerabilities were addressed this month.
Two had previously been publicly disclosed, while one was already being actively exploited.
CVE-2026-68820 – Windows Ancillary Function Driver for WinSock Elevation of Privilege
The most urgent vulnerability in this month's release is CVE-2026-68820, an elevation of privilege vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys).
Successful exploitation can allow a locally authenticated attacker to gain SYSTEM-level privileges without requiring user interaction.
More importantly, this isn't a theoretical attack path.
Check Point Research identified the vulnerability being exploited by the DPRK-linked Lazarus Group as part of its long-running Operation Dream Job campaign.
During the campaign, attackers exploited CVE-2026-68820 to obtain SYSTEM privileges and deploy a new version of FudModule, a kernel-mode rootkit designed to interfere with endpoint security visibility.
The campaign demonstrates why actively exploited vulnerabilities should be treated differently from vulnerabilities that exist only as potential attack paths.
If affected systems are present within your environment, CVE-2026-68820 should be treated as a priority for remediation.
CVE-2026-62832: Windows User Profile Service Elevation of Privilege
Microsoft has also patched CVE-2026-62832, a publicly disclosed vulnerability affecting the Windows User Profile Service.
The vulnerability could allow an authenticated attacker with credentials for another local account to manipulate another user's registry hive.
Successful exploitation could enable access to or modification of another user's data and ultimately allow the attacker to gain administrator privileges. No user interaction is required.
The vulnerability appears to correspond with the previously disclosed LegacyHive technique, which demonstrated how non-administrator users could potentially manipulate registry behaviour to execute commands with elevated privileges.
CVE-2026-72971 – Windows Container Isolation FS Filter Driver
The third zero-day addressed this month is CVE-2026-72971, affecting the Windows Container Isolation FS Filter Driver.
The vulnerability involves improper link resolution before file access and could allow an authorised attacker to perform local tampering.
Microsoft has confirmed that the vulnerability had been publicly disclosed before a security update was available.
400 Vulnerabilities. What Should Security Teams Actually Do?
This month's Patch Tuesday highlights a problem security teams increasingly face.
Finding vulnerabilities isn't the difficult part anymore. Deciding what needs fixing first is.
A list containing hundreds of CVEs doesn't automatically tell you which vulnerabilities create meaningful risk within your environment.
Security teams need context.
-
Is the vulnerable software actually deployed?
-
Which assets are affected?
-
Is the vulnerability actively exploited?
-
Is the affected system exposed?
-
What privileges could an attacker gain?
-
Are there existing security controls reducing the likelihood of exploitation?
-
And, crucially, has the vulnerability actually been remediated?
That last question matters.
Identifying a vulnerability and creating another item in a dashboard doesn't reduce risk. The loop only closes when the vulnerability is understood, prioritised and fixed.
From Vulnerability Detection to Remediation
At CybaVerse, our approach is built around closing that security loop.
Through CybaOps and our Cyber Operators, organisations can bring asset visibility, vulnerability management, detection, response and remediation together rather than managing each as a disconnected security activity.
Our Find, Analyse, Fix, Operate (FAFO) methodology focuses on moving security issues through the entire lifecycle:
Find the vulnerabilities, threats and weaknesses affecting your environment.
Analyse them in the context of your assets, exposure and actual risk.
Fix the issues that matter rather than allowing remediation queues to grow indefinitely.
Operate continuously, maintaining visibility as vulnerabilities, assets and threats change.
Because with hundreds of vulnerabilities appearing in a single Patch Tuesday, organisations don't need another list of everything that could potentially go wrong.
They need to know what matters, what to fix and whether it actually got fixed.
What Should You Prioritise Following August Patch Tuesday?
Organisations should review Microsoft's August 2026 security updates and identify affected assets as soon as possible.
Particular priority should be given to CVE-2026-68820 due to confirmed exploitation in the wild, followed by the other publicly disclosed zero-days and Critical vulnerabilities relevant to your environment.
Teams should also verify that updates have been successfully deployed rather than assuming that issuing a patch means remediation is complete.
Microsoft itself describes keeping endpoints up to date as a pillar of basic security hygiene, with automated patching helping organisations reduce exposure to known vulnerabilities.
But effective vulnerability management goes further than patch deployment.
It requires continuous visibility of your assets, an understanding of which vulnerabilities affect them, prioritisation based on risk and confirmation that remediation has actually happened.
Close the Loop on Vulnerability Management
Another Patch Tuesday. Another 400 vulnerabilities.
The answer isn't to chase 400 CVEs individually.
It's to have a security operation capable of continuously finding weaknesses, understanding which ones create genuine risk and driving them through to remediation.
Find. Analyse. Fix. Operate.
That's how you turn vulnerability data into a stronger security posture.
To access the full description of each vulnerability and the systems it affects, you can view the full report here.