Microsoft released a broad security update covering roughly 398 to 421 vulnerabilities across Windows, Office, Exchange, SharePoint, Azure, .NET, Teams, and other enterprise products, with 42 rated Critical. The most urgent issue is CVE-2026-68820, an actively exploited elevation-of-privilege flaw in the Windows afd.sys Ancillary Function Driver for WinSock that can let an attacker with code execution gain SYSTEM privileges; reporting linked observed exploitation to Lazarus activity. Microsoft also addressed publicly disclosed flaws including CVE-2026-62832, and researchers warned it could be chained with the afd.sys bug for full system compromise.
The release also fixes multiple high-impact server-side and enterprise-facing vulnerabilities, including critical or high-severity remote code execution bugs in Windows iSCSI Target Service (CVE-2026-65791, CVE-2026-65679), Windows GDI+ (CVE-2026-62822), Windows DHCP Server (CVE-2026-62823), Remote Desktop Client (CVE-2026-62824), Windows SMBv3 Server (CVE-2026-62790, CVE-2026-62800), and Microsoft Office (CVE-2026-70130), alongside spoofing and privilege-escalation issues in Azure Entra ID (CVE-2026-62869), Windows NAT (CVE-2026-56179), Exchange Server (CVE-2026-62911), .NET Framework (CVE-2026-62872), and Windows DNS (CVE-2026-62778). Microsoft also completed remediation of an on-premises SharePoint exploit chain by patching CVE-2026-63520 after July’s fix for CVE-2026-55040, prompting defenders to prioritize the exploited kernel flaw, exposed network services, and fully update SharePoint farms.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
38 events from the most recent confirmed update back to the earliest known activity.
After public disclosure of the ShieldBreak Windows Defender privilege-escalation zero-day, Microsoft said it was aware of the reported vulnerability and was actively investigating the validity and potential applicability of the claims. This was the company's first explicit public response to the reported patch bypass.
Microsoft said the Lazarus Group was behind in-the-wild exploitation of Windows zero-day CVE-2026-68820. The article says Lazarus targeted defense, aerospace, and aviation job seekers using PDFs and a trojanized reader to compromise victim machines.
Microsoft's August 2026 Patch Tuesday release fixed 48 remote code execution vulnerabilities affecting Office applications and components, including Excel, Word, Outlook, PowerPoint, and the Office graphics component. The article highlighted document-borne Office flaws as especially attractive to phishing operators because users are likely to open emailed or shared files.
Microsoft's August 2026 Patch Tuesday release included CVE-2026-62815 in Microsoft QUIC and CVE-2026-59124 in HPC Pack, both unauthenticated remote code execution vulnerabilities requiring no user interaction. The reference says HPC Pack flaw CVE-2026-59124 was rated more likely to be exploited, while none of the four server-side CVSS 9.8 flaws were marked as actively exploited at release.
In its August 2026 Patch Tuesday release, Microsoft disclosed CVE-2026-62893, a Windows Deployment Services TFTP Server remote code execution vulnerability caused by a use-after-free. The flaw allows unauthenticated code execution over a network, carries a CVSS score of 9.8, and was assessed by Microsoft as more likely to be exploited.
Microsoft's August 2026 Patch Tuesday disclosures included CVE-2026-65665, a SharePoint Server remote code execution vulnerability caused by deserialization of untrusted data. Talos described it as allowing an authorized attacker to execute code over a network and rated it CVSS 8.8.
Adobe released five security bulletins in August 2026 covering 51 CVEs across ColdFusion, Campaign Classic, Commerce, Lightroom Classic, and Content Credentials SDK. Adobe assigned Campaign Classic and ColdFusion the highest deployment priority and said none of the patched flaws were publicly known or under active attack at release.
Rapid7 noted that Microsoft did not initially publish desktop browser fixes when August 2026 Patch Tuesday content went live, but Edge desktop security updates appeared a few hours later the same day. The update followed Chrome's August 6 Stable Channel release.
The Canadian Centre for Cyber Security published advisory AV26-804 covering Microsoft's August 2026 vulnerabilities. It urged users and administrators to review Microsoft's security updates, apply mitigations, and install necessary patches.
Microsoft published CVE-2026-62800, another high-severity Windows SMB Server heap-based buffer overflow that allows authorized network-based code execution. The entry covers a broad range of Windows client and server builds.
Microsoft published CVE-2026-62790, a high-severity heap-based buffer overflow in Windows SMB Server that allows an authorized attacker to execute code over a network. The advisory lists affected Windows 10, Windows 11, and Windows Server versions.
In the August 2026 Patch Tuesday release, Microsoft disclosed CVE-2026-62878, a critical Windows DNS Server remote code execution vulnerability with CVSS 9.8. The flaw can be triggered remotely without authentication or user interaction, and the Zero Day Initiative characterized it as wormable.
Microsoft published CVE-2026-62778, a high-severity Windows DNS elevation-of-privilege vulnerability involving use-after-free and race-condition characteristics. The flaw allows an unauthorized attacker to elevate privileges over a network.
Microsoft received and disclosed CVE-2026-62869, an Azure Entra ID spoofing vulnerability caused by insufficient verification of data authenticity. The flaw could allow an authorized attacker to perform spoofing over a network.
Microsoft received and disclosed CVE-2026-70130, a heap-based buffer overflow in Microsoft Office that allows unauthorized local code execution. Affected products include Microsoft 365 Apps for Enterprise, Office 2019, and Office LTSC 2021 and 2024.
Microsoft published CVE-2026-56179, a high-severity Windows Network Address Translation spoofing vulnerability caused by an origin validation error. The flaw allows unauthorized spoofing over an adjacent network and affects Windows 11 and Windows Server 2025 builds.
Microsoft published CVE-2026-66802, a high-severity remote code execution vulnerability affecting Windows Device Health Attestation and Azure Attestation service components. The flaw is tied to improper synchronization and use-after-free behavior.
Microsoft published CVE-2026-65791, a critical heap-based buffer overflow in Windows iSCSI Target Service with CVSS 9.8. The flaw allows unauthorized remote code execution over a network across multiple Windows Server releases and Windows 10 Version 1607.
Microsoft published CVE-2026-65679, a high-severity heap-based buffer overflow in Windows iSCSI Target Service that allows unauthorized remote code execution over a network. The advisory lists affected Windows 10 and Windows Server versions from 2012 through 2025.
Microsoft received and published CVE-2026-62911, an Exchange Server authentication bypass by capture-replay vulnerability that allows an authorized attacker to elevate privileges over a network. Affected products include Exchange Server 2016, 2019, and Subscription Edition.
Microsoft published CVE-2026-62872, a high-severity .NET Framework incorrect authorization flaw that allows an authorized attacker to elevate privileges over a network. The advisory spans multiple .NET Framework branches across many Windows client and server versions.
Microsoft published CVE-2026-62822, a high-severity Windows GDI+ integer overflow or wraparound vulnerability that can enable remote code execution over a network. The entry covers multiple Windows 10, Windows 11, and Windows Server versions.
Microsoft published CVE-2026-62824, a high-severity stack-based buffer overflow in Remote Desktop Client that can allow network-based remote code execution with user interaction. Affected products include Windows 10 Version 1607 and several Windows Server releases.
Microsoft published CVE-2026-62823, a high-severity heap-based buffer overflow in Windows DHCP Server that allows adjacent-network remote code execution without privileges or user interaction. The advisory lists affected Windows Server releases and older Windows 10 builds.
CISA added the actively exploited Windows Ancillary Function Driver for WinSock privilege-escalation flaw CVE-2026-68820 to its Known Exploited Vulnerabilities Catalog. The agency set an August 25, 2026 remediation deadline for federal civilian agencies covered by BOD 26-04.
Check Point reported that North Korean Lazarus actors exploited the Windows afd.sys zero-day CVE-2026-68820 in attacks to deploy a new version of the FudModule kernel-mode rootkit. This added technical detail to the previously reported Lazarus attribution for the vulnerability's in-the-wild exploitation.
Check Point Research said Lazarus used CVE-2026-68820 in its Operation Dream Job campaign. Microsoft itself did not publicly attribute the exploitation.
Microsoft's August 2026 updates patched CVE-2026-63520, the remote code execution component of the on-premises SharePoint exploit chain. Together with July's CVE-2026-55040 fix, this completed remediation of the two-part chain.
Microsoft also patched CVE-2026-72971 in the August 2026 release. The flaw had been publicly disclosed before patching and was assessed as unlikely to be exploited.
Microsoft's August 2026 updates patched CVE-2026-62832 in the Windows User Profile Service. Sources say the flaw had been publicly disclosed before release and Microsoft assessed it as likely to be exploited.
In the August 2026 release, Microsoft patched CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock that can grant SYSTEM privileges after code execution on a machine. Microsoft marked the bug as actively exploited in the wild.
Microsoft released its August 2026 Patch Tuesday updates, addressing hundreds of vulnerabilities across Windows, Office, Azure, Exchange, SharePoint, .NET, and other products. Multiple sources describe this as the monthly security release for August 11, 2026.
Check Point Research reported the actively exploited Windows AFD.sys privilege-escalation flaw later tracked as CVE-2026-68820 to the Microsoft Security Response Center. The reference says Check Point had observed zero-day exploitation in Operation Dream Job since at least early July 2026.
Microsoft's July update patched CVE-2026-55040, the authentication bypass component of the on-premises SharePoint exploit chain. Rapid7 said this July patch already broke the demonstrated chain.
Two days after Rapid7's report, Microsoft confirmed that remediation for the SharePoint exploit chain would be delivered across the July and August update cycles. This established a staged fix for the authentication bypass and RCE components.
Rapid7 Labs reported an on-premises SharePoint exploit chain involving CVE-2026-55040 and CVE-2026-63520 to Microsoft. The report date is explicitly given as May 18.
Researcher Nightmare Eclipse released a proof-of-concept called ShieldBreak that reportedly bypasses Microsoft's July 2026 patch for CVE-2026-50656, the RoguePlanet Microsoft Defender vulnerability. The reference presents this as a newly released technical disclosure showing a patch bypass.
A Chinese-language blog published a proof-of-concept exploit for Windows Kernel flaw CVE-2026-62737 that could cause a system crash. The disclosure was cited in CrowdStrike's August 2026 Patch Tuesday analysis as evidence the vulnerability had been publicly discussed before Microsoft's patch release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
expel.com
Open sourcemalware.news
Open sourcecybersecuritynews.com
Open sourcetechrepublic.com
Open sourcecvefeed.io
Open sourceautomox.com
Open sourcezerodayinitiative.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.