Microsoft’s August 2026 Patch Tuesday update fixes 398 newly disclosed security vulnerabilities across Windows, Office, Exchange Server and several other products, including one Windows flaw that attackers are already exploiting.
Microsoft has classified 42 of the vulnerabilities as critical. Most of the remaining issues are rated high severity, while two vulnerabilities were already publicly known before the updates arrived.
The most urgent problem for Windows systems is CVE-2026-68820, a vulnerability in the Windows auxiliary function driver for Winsock. Microsoft says the flaw is already being exploited in real attacks.
Microsoft August 2026 security update overview
| Area | Details |
|---|---|
| Total new vulnerabilities | 398 |
| Critical vulnerabilities | 42 |
| Actively exploited Windows flaw | CVE-2026-68820 |
| Windows vulnerabilities | More than 200 |
| Office vulnerabilities | 128 |
| Exchange Server vulnerabilities | 7 |
| Edge Chromium fixes | 41 additional vulnerabilities |
| Next Patch Tuesday | September 8, 2026 |
The patches also cover products and services including Teams, Hyper V, Windows Defender, Visual Studio and Microsoft cloud services.
Winsock flaw is already being exploited
CVE-2026-68820 is a use after free vulnerability affecting the Windows auxiliary function driver for Winsock.
An attacker who successfully exploits the flaw can gain elevated privileges and execute code with system level permissions.
The vulnerability does not provide remote code execution by itself. An attacker would need to combine it with another exploit that first allows code to run on the target system.
Even with that requirement, active exploitation makes CVE-2026-68820 one of the highest priority fixes in this month’s security release.
Windows 10, Windows 11 and supported Windows Server versions receive security updates where applicable.
Windows 10 officially reached the end of normal support in October 2025, but systems enrolled in Microsoft’s Extended Security Updates program continue receiving security patches through October 2027.
Microsoft fixes 18 critical Windows vulnerabilities
Microsoft has classified 18 Windows vulnerabilities in the August update as critical.
One of them, CVE-2026-62878, affects Windows DNS Server.
The flaw is a buffer overflow vulnerability that can allow remote code execution with elevated privileges without requiring interaction from the person using the affected machine.
Another critical issue, CVE-2026-62893, affects the Trivial File Transfer Protocol server component of Windows Deployment Services.
An attacker can reportedly exploit the flaw through UDP port 69 to inject and execute code without interaction. The vulnerability results from software attempting to use an object without first confirming that the object still exists.

Windows QUIC is also affected by CVE-2026-62815, another remote code execution vulnerability that can allow injected code to run without interaction.
Microsoft additionally fixed CVE-2026-59124 in its High Performance Computing Pack. That issue also allows remote code execution, but it is rated high rather than critical because the affected HPC Pack feature is not enabled by default.
Office receives 128 security fixes
Microsoft Office accounts for a substantial portion of the August security release, with 128 vulnerabilities addressed.
Twenty two of those are critical remote code execution flaws.
Five critical issues are located in the Office graphics component.
Some critical Office vulnerabilities can be triggered through the preview pane, meaning a malicious document may not necessarily have to be fully opened for exploitation to occur.
Other high severity remote code execution vulnerabilities require someone to open a specially crafted malicious Office file.
The volume of Office fixes makes the update particularly important for business systems where documents arrive regularly through email, file sharing services and collaboration platforms.
Exchange Server flaw could allow complete account takeover
Microsoft has patched seven vulnerabilities in Exchange Server.
The most serious is CVE-2026-62911, a critical elevation of privilege vulnerability.
Successful exploitation can allow an attacker to bypass authentication and gain access to email accounts. The attacker could potentially read messages, send email and download attachments.
The vulnerability was previously demonstrated successfully during the Pwn2Own security competition in Berlin in May.
Another Exchange Server issue, CVE-2026-62913, allows remote code execution and is classified as high severity.
The remaining Exchange vulnerabilities in the update are also rated high.
Edge gets 41 additional Chromium fixes
Microsoft Edge has received a separate security update to version 151.0.4129.78.
That release is based on Chromium 151.0.7922.109 and addresses 41 Chromium vulnerabilities.
Those 41 issues are not included in Microsoft’s total of 398 vulnerabilities for the August Patch Tuesday release.
The Chromium project is also expected to receive another security update addressing five additional vulnerabilities.
Installing the August updates should be a priority
The large number of vulnerabilities makes the August 2026 update significant, but the actively exploited Winsock flaw gives Windows owners a more immediate reason to install it.
Systems that delay security updates remain exposed to vulnerabilities for which technical details may already be available to attackers.
Businesses running Exchange Server, Windows DNS Server, Office or Windows Deployment Services should also review the critical vulnerabilities affecting those products rather than treating the release as a routine desktop update.
For most Windows PCs, the practical step is simple: check Windows Update and install the August security patches as soon as they are available.
Microsoft’s next scheduled Patch Tuesday is September 8, 2026.



Discussion (0)
Be the first to comment.