Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly
Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the difference attributed to counting method or update scope.
The most urgent issue in the supplied coverage is CVE-2026-68820, a use-after-free elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), a core Windows networking driver. The flaw can let a locally authenticated attacker win a race condition and gain SYSTEM privileges, and it was reported as actively exploited in the wild.
TechGig, Mallory.ai, and CyberHub coverage also identified two publicly disclosed Windows flaws in the release: CVE-2026-62832 in the Windows User Profile Service and CVE-2026-72971 in the Windows Container Isolation FS Filter Driver. Separate reporting also highlighted remote-code-execution fixes affecting Windows DNS Server, Windows Deployment Services TFTP Server, Microsoft QUIC, and HPC Pack where those services are deployed.
Sources
- Qualys ThreatPROTECT: Microsoft Patch Tuesday, August 2026 Security Update Review
- Security Affairs: Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE
- TechGig: Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, 3 Zero-Days
- Mallory.ai: Microsoft Fixes 420 Flaws Including Exploited Windows Privilege Escalation Bugs
- CyberHub Podcast: Cisco VPNs Under Active Attack, Microsoft Drops 421 Patches ...