August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

By George Bailey   Published: 08/20/26   Updated: 08/20/26   3 min read
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

The Numbers That Actually Matter

CrowdStrike says Microsoft fixed 415 vulnerabilities in August 2026, including one exploited zero-day, three publicly disclosed zero-days, and 62 critical issues. The two dominant exploit classes are elevation of privilege with 174 patches and remote code execution with 109, which tells you this month is not just about internet-facing services. It is also about what an attacker can do after landing somewhere local.

Windows took 233 patches, Extended Security Updates added 192, and Microsoft Office accounted for 125. That spread matters because it guarantees ownership friction: infrastructure teams, endpoint teams, and productivity-platform owners all have part of the cleanup burden.

Start With The Exploited And Publicly Disclosed Flaws

The exploited zero-day is CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock, a use-after-free local privilege-escalation flaw that can hand a low-privileged attacker SYSTEM if they win the race condition. That is exactly the kind of bug that turns an initial foothold into durable control.

CrowdStrike also flags publicly disclosed Windows privilege-escalation issues CVE-2026-62832 in User Profile Service and CVE-2026-62737 in the Windows kernel, plus CVE-2026-72971 in the Windows Container Isolation FS Filter Driver. Even without confirmed in-the-wild abuse for all three, disclosure changes the timetable because exploit development pressure is now public.

Which Remote Services Deserve Fastest Action

The remote-code-execution list is where this month gets expensive for organizations with neglected infrastructure. CrowdStrike highlights CVE-2026-62815 in Microsoft QUIC, CVE-2026-62893 in Windows Deployment Services TFTP Server, four Windows DNS Server bugs led by CVE-2026-62878, CVE-2026-65791 in Windows iSCSI Target Service, CVE-2026-62818 in Active Directory Certificate Services, and CVE-2026-62823 in Windows DHCP Server.

The pattern is ugly because these are not fringe components. DNS, DHCP, AD CS, deployment services, and QUIC-backed services all sit on shared enterprise plumbing. A weak patch month on those systems becomes a trust and availability problem very quickly.

Why SharePoint And Office Still Matter

CrowdStrike also points to multiple critical SharePoint Server bugs, including CVE-2026-62827, CVE-2026-64921, and CVE-2026-65665. That makes SharePoint a repeat concern this month rather than a one-headline story, and it means collaboration infrastructure needs its own explicit validation path.

On the client side, the long list of Excel, Office, Word, and Office Graphics Component flaws is a reminder that local-document execution paths still matter. They may not generate the same urgency as an exposed DNS server, but they remain useful to attackers chaining phishing, malware delivery, and privilege escalation.

What To Do Today

Use this advisory as a triage board, not a patch-count recap.

Source Context

CyberExperts used CrowdStrike's Patch Tuesday analysis as the primary source and kept the article anchored to the items most useful for defenders: the total scope, the exploited and publicly disclosed flaws, and the network services most likely to create painful incidents if patching slips.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading