Skip to main content
VTechFusion Technologies
Microsoft's August 2026 Patch Tuesday: 421 CVEs, One Exploited Zero-Day
InsightsNewsIndustry & AI News
Industry & AI News5 min readAugust 18, 2026

Microsoft's August 2026 Patch Tuesday: 421 CVEs, One Exploited Zero-Day

VT

VTechFusion Team

VTechFusion Technologies

Microsoft's August 2026 Patch Tuesday addressed 421 CVEs — one of its largest monthly updates in recent memory — including CVE-2026-68820, a use-after-free elevation-of-privilege flaw in the Windows Ancillary Function Driver (afd.sys) that was already under active exploitation before the patch shipped.

What Actually Needs Immediate Attention

  • CVE-2026-68820 — actively exploited, allows attackers to elevate privileges to System level via a use-after-free bug in afd.sys
  • CVE-2026-62832 — publicly disclosed before a patch existed, an improper link resolution bug in Windows User Profile Service that can let an authenticated attacker access or modify another user's data and gain administrator privileges
  • 62 of the 421 fixes carry a Critical severity rating

Where the Volume Actually Sits

The 421 CVEs break down as 236 in Windows itself, 98 in Office, 98 in Office 2016 specifically, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, 7 in Exchange Server, and smaller counts elsewhere. The SharePoint Server and Exchange Server counts are worth flagging specifically — both are common on-premises targets for opportunistic scanning once a patch cycle publicly reveals what was vulnerable.

The Practical Takeaway for IT Teams

With one confirmed actively-exploited flaw and two additional publicly disclosed zero-days in the same release, this is not a routine maintenance-window patch cycle — the privilege-escalation flaw in particular should be prioritized ahead of the broader batch, especially on any internet-facing or shared Windows infrastructure. Publicly disclosed zero-days tend to see a sharp rise in opportunistic scanning within days of disclosure, whether or not exploitation was observed before the patch.

Filed under:Industry & AI News
All News

Frequently Asked Questions

Which August 2026 Patch Tuesday vulnerability is being actively exploited?

CVE-2026-68820, a use-after-free elevation-of-privilege flaw in the Windows Ancillary Function Driver (afd.sys), was confirmed under active exploitation before Microsoft's patch shipped, letting attackers elevate privileges to System level.

How many vulnerabilities did Microsoft fix in the August 2026 update?

421 CVEs total, including 62 rated Critical, with the bulk concentrated in Windows itself (236) and Office/Office 2016 (98 each).

Media & Press Enquiries

For editorial enquiries, expert commentary, or case study access.

Start Today

Ready to Build Something Great?

Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.