Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.Patch Tuesday addresses 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege.When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today.Therefore, the number of flaws does not include some flaws in Mariner, Microsoft Teams, Microsoft Azure, Microsoft Entra, Microsoft Office, and Power Apps that were fixed by Microsoft earlier this month.While this Patch Tuesday is not as large as last month's, which fixed 570 flaws, it is still very large compared to the previous month.Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its software products.This month's Patch Tuesday fixes three zero-day vulnerabilities, with one exploited in attacks and two publicly disclosed.Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available.The actively exploited zero-day vulnerabilities addressed during this month's Patch Tuesday are:Microsoft has patched an actively exploited vulnerability in the Windows Ancillary Function Driver for WinSock that grants SYSTEM privileges."Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally," warns Microsoft."A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required," continued Microsoft.The flaws were credited to Moshe Marelus and David Driker with Checkpoint.In a report released today, Check Point says the flaw was exploited in zero-day attacks by the North Korean threat actors known as Lazarus to deploy malware."During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit," said Check Point.Microsoft has not shared any details on how the flaws were exploited.Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges."Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally," explains Microsoft."An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required," continued Microsoft.While Microsoft attributed the flaw to an anonymous researcher, the details match a zero-day vulnerability called "LegacyHive" that was disclosed by a security researcher named Nightmare Eclipse last month.Tharros principal vulnerability analyst Will Dormann previously said that non-admin users can exploit LegacyHive to modify the registry hive to launch commands with administrative privileges when the when the admin account logs into a compromised device.Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges."Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally," explains Microsoft."An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required," continued Microsoft.Microsoft has not shared any details on where the flaw was disclosed but attributed the discovery to yhw & txz.Below is the complete list of resolved vulnerabilities in the August 2026 Patch Tuesday updates, excluding flaws fixed before today.To access the full description of each vulnerability and the systems it affects, you can view the full report here.
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.









