Microsoft August 2026 Update Fixes 398 Security Flaws Including Actively Exploited Windows Bug

news
Microsoft August 2026 Update Fixes 398 Security Flaws Including Actively Exploited Windows Bug

Microsoft’s August 2026 Patch Tuesday update fixes 398 newly disclosed security vulnerabilities across Windows, Office, Exchange Server and several other products, including one Windows flaw that attackers are already exploiting.

Microsoft has classified 42 of the vulnerabilities as critical. Most of the remaining issues are rated high severity, while two vulnerabilities were already publicly known before the updates arrived.

The most urgent problem for Windows systems is CVE-2026-68820, a vulnerability in the Windows auxiliary function driver for Winsock. Microsoft says the flaw is already being exploited in real attacks.

Microsoft August 2026 security update overview

AreaDetails
Total new vulnerabilities398
Critical vulnerabilities42
Actively exploited Windows flawCVE-2026-68820
Windows vulnerabilitiesMore than 200
Office vulnerabilities128
Exchange Server vulnerabilities7
Edge Chromium fixes41 additional vulnerabilities
Next Patch TuesdaySeptember 8, 2026

The patches also cover products and services including Teams, Hyper V, Windows Defender, Visual Studio and Microsoft cloud services.

Winsock flaw is already being exploited

CVE-2026-68820 is a use after free vulnerability affecting the Windows auxiliary function driver for Winsock.

An attacker who successfully exploits the flaw can gain elevated privileges and execute code with system level permissions.

The vulnerability does not provide remote code execution by itself. An attacker would need to combine it with another exploit that first allows code to run on the target system.

Even with that requirement, active exploitation makes CVE-2026-68820 one of the highest priority fixes in this month’s security release.

Windows 10, Windows 11 and supported Windows Server versions receive security updates where applicable.

Windows 10 officially reached the end of normal support in October 2025, but systems enrolled in Microsoft’s Extended Security Updates program continue receiving security patches through October 2027.

Microsoft fixes 18 critical Windows vulnerabilities

Microsoft has classified 18 Windows vulnerabilities in the August update as critical.

One of them, CVE-2026-62878, affects Windows DNS Server.

The flaw is a buffer overflow vulnerability that can allow remote code execution with elevated privileges without requiring interaction from the person using the affected machine.

Another critical issue, CVE-2026-62893, affects the Trivial File Transfer Protocol server component of Windows Deployment Services.

An attacker can reportedly exploit the flaw through UDP port 69 to inject and execute code without interaction. The vulnerability results from software attempting to use an object without first confirming that the object still exists.

Windows QUIC is also affected by CVE-2026-62815, another remote code execution vulnerability that can allow injected code to run without interaction.

Microsoft additionally fixed CVE-2026-59124 in its High Performance Computing Pack. That issue also allows remote code execution, but it is rated high rather than critical because the affected HPC Pack feature is not enabled by default.

Office receives 128 security fixes

Microsoft Office accounts for a substantial portion of the August security release, with 128 vulnerabilities addressed.

Twenty two of those are critical remote code execution flaws.

Five critical issues are located in the Office graphics component.

Some critical Office vulnerabilities can be triggered through the preview pane, meaning a malicious document may not necessarily have to be fully opened for exploitation to occur.

Other high severity remote code execution vulnerabilities require someone to open a specially crafted malicious Office file.

The volume of Office fixes makes the update particularly important for business systems where documents arrive regularly through email, file sharing services and collaboration platforms.

Exchange Server flaw could allow complete account takeover

Microsoft has patched seven vulnerabilities in Exchange Server.

The most serious is CVE-2026-62911, a critical elevation of privilege vulnerability.

Successful exploitation can allow an attacker to bypass authentication and gain access to email accounts. The attacker could potentially read messages, send email and download attachments.

The vulnerability was previously demonstrated successfully during the Pwn2Own security competition in Berlin in May.

Another Exchange Server issue, CVE-2026-62913, allows remote code execution and is classified as high severity.

The remaining Exchange vulnerabilities in the update are also rated high.

Edge gets 41 additional Chromium fixes

Microsoft Edge has received a separate security update to version 151.0.4129.78.

That release is based on Chromium 151.0.7922.109 and addresses 41 Chromium vulnerabilities.

Those 41 issues are not included in Microsoft’s total of 398 vulnerabilities for the August Patch Tuesday release.

The Chromium project is also expected to receive another security update addressing five additional vulnerabilities.

Installing the August updates should be a priority

The large number of vulnerabilities makes the August 2026 update significant, but the actively exploited Winsock flaw gives Windows owners a more immediate reason to install it.

Systems that delay security updates remain exposed to vulnerabilities for which technical details may already be available to attackers.

Businesses running Exchange Server, Windows DNS Server, Office or Windows Deployment Services should also review the critical vulnerabilities affecting those products rather than treating the release as a routine desktop update.

For most Windows PCs, the practical step is simple: check Windows Update and install the August security patches as soon as they are available.

Microsoft’s next scheduled Patch Tuesday is September 8, 2026.

Discover: News

Discussion (0)

Be the first to comment.