Microsoft released its August 2026 security updates to address 420 newly disclosed vulnerabilities across its product portfolio, according to alerts published by CSIRT Italia and CERT-PY. The advisories highlight one zero-day and three Windows flaws drawing particular attention because they are either under active exploitation or have publicly available proof-of-concept code: CVE-2026-68820, CVE-2026-72971, and CVE-2026-62832.
CVE-2026-68820 affects the Windows Ancillary Function Driver for WinSock and is a use-after-free bug that could allow a locally authenticated attacker to win a race condition and obtain SYSTEM privileges. CVE-2026-72971, in the Windows Container Isolation FS Filter Driver, and CVE-2026-62832, in the Windows User Profile Service, are link-following issues that can enable unauthorized local actions; the latter could let an attacker access or modify another local user’s registry hive and potentially escalate to administrative privileges. The notices urge organizations to deploy the updates through Windows Update and review Microsoft’s MSRC Update Guide and release notes for affected products.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT Italia published alert AL04/260812/CSIRT-ITA covering Microsoft's August 2026 security updates and recommending that impacted products be updated through Windows Update. The alert reported a systemic impact score of 76.66 classified as Critico.
The August 2026 bulletin specifically highlighted CVE-2026-68820, CVE-2026-72971, and CVE-2026-62832 as vulnerabilities with either publicly available proof-of-concept code or active exploitation. The flaws affect the Windows Ancillary Function Driver for WinSock, Windows Container Isolation FS Filter Driver, and Windows User Profile Service, respectively.
Microsoft's August 2026 monthly security updates fixed 420 newly disclosed vulnerabilities across affected products, including one zero-day. The bulletin covered issues across categories such as elevation of privilege, remote code execution, spoofing, information disclosure, tampering, and denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.