Security experts say prioritization should be the main focus for the August updates, not the massive CVE volume.

August 11, 2026

Following its earlier warning that large-volume security updates could become the new norm for the foreseeable future, Microsoft this week released fixes for 421 unique CVEs, including two zero-day vulnerabilities.

Of these, 236 vulnerabilities affect Windows, while 98 each affect Office and Office 2016. SharePoint Server accounted for 30 vulnerabilities, followed by Developer Tools, with 26; Azure, with 17; and Exchange Server for another seven. Microsoft assessed 44 of the CVEs as critical severity and a vast majority of the others as Important or Moderate severity bugs. In total, 180 of the vulnerabilities in Microsoft's August 2026 update were elevation of privilege (EoP) issues that give attackers the ability to gain full SYSTEM level privileges on affected devices.

This marks the second consecutive month in which Microsoft's Patch Tuesday has been significantly larger than its typical security updates. July's release was even bigger, addressing 622 unique CVEs. Microsoft has warned organizations to expect elevated patch volumes in the near term as the company, like other software vendors, increasingly uses AI tools to identify vulnerabilities in its products.