Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

By George Bailey   Published: 08/11/26   Updated: 08/11/26   5 min read
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Microsoft's August 2026 Patch Tuesday is not just a big-number release. It is a prioritization problem with one actively exploited Windows kernel flaw, two other publicly disclosed zero-days, multiple unauthenticated 9.8 remote-code-execution bugs, and a SharePoint chain that matters to any organization still carrying on-premises collaboration infrastructure.

The practical question is not whether Microsoft shipped enough fixes. It is whether your team can separate the patch-now items from the patch-soon items before attackers or internal delay do that sorting for you.

What Changed

This month's release covers roughly 400 flaws, but the useful signal is much narrower than the total. The highest-value work starts with the flaws that already have exploitation or give an unauthenticated attacker a clean remote path.

The actively exploited zero-day is CVE-2026-68820, a Windows Ancillary Function Driver for WinSock elevation-of-privilege bug in afd.sys. According to public reporting, an attacker who already has code execution on a Windows machine can use the flaw to escalate to SYSTEM, and Check Point linked it to Lazarus activity.

The two other publicly disclosed zero-days called out in reporting are:

Those are not the only issues worth urgent attention. The remote attack surface is where this release gets more dangerous for exposed or hard-to-inventory services.

The Flaws Most Teams Should Triage First

If you need a fast patch queue, start here:

That list is where most defenders should spend their first hour, because it tells you which owners need to be paged and which services deserve an immediate exposure check.

Why CyberExperts Flagged It

Patch Tuesday coverage is often too broad to be useful. A list of hundreds of bugs does not help unless someone translates it into an order of operations.

This one deserves attention because it mixes three different problem types that create operational drag fast: a live exploited local privilege-escalation flaw, unauthenticated remote services that can be internet- or intranet-reachable, and enterprise platforms like SharePoint where the real risk is not just server compromise but document, identity, and downstream trust exposure.

The teams that lose time on releases like this are usually not the ones that ignored the patch note. They are the ones that cannot answer basic questions quickly enough: Do we run this service? Is it exposed? Who owns it? How fast can we move without breaking something more important?

What Defenders May Be Underestimating

The easy mistake is to treat Patch Tuesday as one change window instead of several different risk classes.

A flaw like CVE-2026-68820 matters most where an attacker already has a foothold and needs SYSTEM. The DNS, WDS, QUIC, and HPC items matter where exposed services widen the initial-access path. SharePoint matters where authentication, document access, and app trust overlap. Those are different triage lanes, different owners, and often different maintenance realities.

That means the operational work should not start with 'How many CVEs did Microsoft fix?' It should start with 'Which of these attack paths exist in our environment today?' Teams that collapse everything into one generic patch bucket are the ones most likely to miss the truly urgent pieces.

What Teams Should Do Next

Source Context

CyberExperts is using BleepingComputer as the primary reference for this article, with additional corroborating detail from public Patch Tuesday coverage that highlighted the actively exploited CVE-2026-68820, the unauthenticated 9.8 RCE set, and the SharePoint CVE-2026-55040 plus CVE-2026-63520 chain.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading