Microsoft's August 2026 security update addresses 790 vulnerabilities: 109 rated Critical, 396 Important. 1 is already exploited in the wild and 2 were publicly disclosed before today.
This month's headline is a single actively exploited zero-day: CVE-2026-68820, a use-after-free EoP in the Windows Ancillary Function Driver for WinSock, already confirmed in KEV. It's the one CVE in this 790-fix batch you cannot leave for next week. Beyond that, the release is heavy on volume — 109 critical and 111 RCE fixes — but light on other confirmed exploitation, with two publicly disclosed EoP/tampering bugs in User Profile Service and the Container Isolation FS Filter Driver rounding out the disclosed-but-not-yet-exploited list.
Patch these first
CVE-2026-68820 (Important, CVSS 7.0) — Windows Ancillary Function Driver for WinSock: Elevation of Privilege — exploited in the wild, CISA KEV
CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0): a use-after-free that lets an already-authenticated local attacker elevate privileges to SYSTEM. It's marked exploited in the wild and is in KEV, so treat it as your top priority patch this cycle regardless of platform — AFD.sys underpins core networking on every supported Windows version, meaning any endpoint or server where a low-priv user or process can execute code is a viable target for local privilege escalation chains. Patch this today.










