Security Bulletin: Microsoft’s August 2026 Patch Tuesday Fixes Nearly 400 Flaws, Including 3 Zero-Days

August 11, 2026by MSPH Admin0

Priority: High — Prompt Patching Recommended

Microsoft’s August 2026 Patch Tuesday is out, and while it’s smaller than last month’s record-breaking release, it still includes three zero-day vulnerabilities — one of which is already being actively exploited by attackers.

The Headline Numbers

Microsoft addressed roughly 398 vulnerabilities this month (vendor counts vary slightly depending on methodology), with 42 rated Critical. Following July’s record 570-flaw release, Microsoft has said the elevated volume reflects a new AI-powered vulnerability discovery system it’s using to scan its codebase — meaning larger-than-usual Patch Tuesdays may continue for the foreseeable future.

The Three Zero-Days

CVE-2026-68820 — Windows AFD.sys Elevation of Privilege (Actively Exploited) This is the month’s most urgent fix. A flaw in the Ancillary Function Driver for WinSock (afd.sys) — a core kernel-mode driver behind the Windows Sockets API — lets a locally authenticated attacker trigger a race condition and gain SYSTEM-level privileges. No user interaction is required. Security researchers note that similar afd.sys flaws have historically been exploited by nation-state threat actors, including groups linked to North Korea.

CVE-2026-62832 — Windows User Profile Service Elevation of Privilege (Publicly Disclosed) An attacker who already has credentials for another local account on a machine can load that user’s registry hive and gain administrator privileges. It was publicly disclosed before a patch was available and is rated “Exploitation More Likely” by Microsoft.

CVE-2026-72971 — Windows Container Isolation Driver Tampering (Publicly Disclosed) A flaw in the driver that underpins Windows Container Isolation (unionfs.sys) could let an attacker tamper with container file integrity. It was publicly disclosed prior to patching, though Microsoft has not seen active exploitation. This one matters most for organizations running containerized Windows workloads.

Other Notable Fixes

  • Microsoft Outlook remote code execution (CVE-2026-70329) and a batch of Important-rated information-disclosure bugs across Excel, Word, and PowerPoint. None are Critical, but Office flaws are frequently weaponized in phishing campaigns using malicious attachments or shared documents — worth extra vigilance from staff regardless of patch status.
  • Critical remote code execution bugs in QUIC and DNS Server, relevant primarily to organizations running affected Windows Server roles.

What This Means for You

  • Systems with local user accounts and shared machines are the priority this month, given the AFD.sys and User Profile Service flaws both hinge on local privilege escalation.
  • Container-based Windows environments should patch the unionfs.sys driver even though it isn’t yet being exploited — public disclosure means an exploit could surface quickly.
  • Office-based phishing risk remains elevated independent of patch status — a good reminder to reinforce attachment and link caution with staff.

Recommended Next Steps

  1. Prioritize deployment of the AFD.sys fix (CVE-2026-68820) across all Windows endpoints — this is the actively exploited flaw.
  2. Patch the User Profile Service and Container Isolation driver vulnerabilities as part of this cycle, especially on shared or multi-user systems.
  3. Apply Outlook and Office updates as part of standard rollout; consider this a good moment to remind staff about phishing hygiene.
  4. Let us know if any systems can’t be updated on the normal schedule so we can discuss interim mitigations.

Leave a Reply

Your email address will not be published. Required fields are marked *