Skip to content

Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly

Share
Source: Badtech.org

Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the difference attributed to counting method or update scope.

The most urgent issue in the supplied coverage is CVE-2026-68820, a use-after-free elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock (afd.sys), a core Windows networking driver. The flaw can let a locally authenticated attacker win a race condition and gain SYSTEM privileges, and it was reported as actively exploited in the wild.

TechGig, Mallory.ai, and CyberHub coverage also identified two publicly disclosed Windows flaws in the release: CVE-2026-62832 in the Windows User Profile Service and CVE-2026-72971 in the Windows Container Isolation FS Filter Driver. Separate reporting also highlighted remote-code-execution fixes affecting Windows DNS Server, Windows Deployment Services TFTP Server, Microsoft QUIC, and HPC Pack where those services are deployed.

Sources

Read more

Oracle August 2026 CPU ships 943 patches, including critical unauthenticated flaws in Fusion Middlew

Oracle released its August 2026 Critical Security Patch Update on August 18 with 943 new patches across its enterprise software portfolio, including 262 for Fusion Middleware, 120 for E-Business Suite, and 66 for Commerce. Covered products include WebLogic Server, PeopleSoft Enterprise PeopleTools, Oracle Internet Directory, Oracle Identity Manager, WebCenter,

By Adam Field Source: Badtech.org