Microsoft’s August Patch Tuesday fixes 421 vulnerabilities, including an actively exploited Windows flaw

· Original article ↗

Summary

Microsoft’s August release fixes 421 vulnerabilities across 29 product families. One Windows privilege-escalation flaw is under active exploitation, while seven critical Windows flaws allow remote code execution without authentication or user interaction.

Key points

  • Microsoft released 421 patches on August 11, covering 29 product families; 64 vulnerabilities were rated Critical.
  • CVE-2026-68820, an Important-severity Windows privilege-escalation flaw affecting most Windows versions, is the only issue Microsoft says is actively exploited.
  • Seven Critical Windows vulnerabilities enable remote code execution without authentication or user interaction; Microsoft considers CVE-2026-62893 more likely to be exploited within 30 days.
  • All 17 highlighted Office vulnerabilities can be triggered through the Preview Pane; none were considered more likely to be exploited within 30 days.
  • Microsoft expects 35 vulnerabilities to be exploited within 30 days, while three were publicly disclosed or under active exploitation at release.
  • Sophos lists protections for several vulnerabilities, including CVE-2026-68820; the article advises downloading the applicable cumulative update from the Windows Update Catalog if not waiting for automatic updates.

Article Details

Vulnerability Types
  • Heap-based buffer overflow
  • Use after free
  • Out-of-bounds read
  • Elevation of privilege
  • Remote code execution
  • Information disclosure
  • Denial of service
  • Spoofing
  • Security feature bypass
  • Tampering
Severity
64 Critical, 356 Important, and one Moderate vulnerabilities in Microsoft's August release.
Affected Versions
  • Most versions of Windows are affected by CVE-2026-68820.
Exploitation Status
active
Exploit Availability
unknown
Patch Status
partial

MITRE ATT&CK

CVE

CVE-2026-24301month. Nineteen vulnerabilities affecting 10 families have already been mitigated, and a twentieth (CVE-2026-24301, a Copilot Web issue) was handled several days later. The average CVSS Base score for those 20 isCVE-2026-58612we’ve been watching continue to develop. Once again we have a lot of multiple-finder vulnerabilities; CVE-2026-58612, an Important-severity PowerShell bug, leads the pack with 17 credited discoverers from around theCVE-2026-61348CVE-2026-61358CVE-2026-61359CVE-2026-61929CVE-2026-61930CVE-2026-62688CVE-2026-62698CVE-2026-62713CVE-2026-62815CVE-2026-62815 -- Microsoft QUIC Remote Code Execution VulnerabilityCVE-2026-62819CVE-2026-62819 -- Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityCVE-2026-62873(The sole differentiator between Office and 365, CVE-2026-62873, is among the group for which patches were issued in advance of Patch Tuesday.) CVE-2026-62878CVE-2026-62878 -- Windows DNS Server Remote Code Execution VulnerabilityCVE-2026-62888CVE-2026-62893CVE-2026-62893 -- Windows Deployment Services TFTP Server Remote Code Execution VulnerabilityCVE-2026-63508CVE-2026-63508 -- Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityCVE-2026-63513CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909,CVE-2026-63515CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909,CVE-2026-63517CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909,CVE-2026-63519CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909,CVE-2026-63520CVE-2026-63524CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909,CVE-2026-63526CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909,CVE-2026-63529CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909,CVE-2026-63532CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657,CVE-2026-63533CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807,CVE-2026-64898CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315,CVE-2026-64899CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317CVE-2026-64903CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317CVE-2026-64909CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317CVE-2026-65657CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317CVE-2026-65665CVE-2026-65775CVE-2026-65788CVE-2026-65789CVE-2026-65789 -- Windows DNS Server Remote Code Execution VulnerabilityCVE-2026-65791CVE-2026-65791 -- Windows iSCSI Target Service Remote Code Execution VulnerabilityCVE-2026-66802CVE-2026-66802 -- Windows Device Health Attestation (DHA) Remote Code Execution VulnerabilityCVE-2026-66804CVE-2026-66807CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317CVE-2026-6726era, the relatively low count of advisories is striking. There are two MITRE-credited items (CVE-2026-6726, CVE-2026-6727) that were patched earlier in the month, but as these are Windows-related we’re simplyCVE-2026-6727relatively low count of advisories is striking. There are two MITRE-credited items (CVE-2026-6726, CVE-2026-6727) that were patched earlier in the month, but as these are Windows-related we’re simply rolling themCVE-2026-68820of Critical severity; 35 CVEs are expected to be exploited within the next 30 days. (One already is; CVE-2026-68820 is an Important-severity Elevation of Privilege issue affecting most versions of Windows.) EightyCVE-2026-69414Just one was publicly disclosed (but not yet exploited) as of release day, with one additional item (CVE-2026-69414) stated by Microsoft to be publicly disclosed by week’s end. (More on post-Tuesday patch activity inCVE-2026-70307Microsoft has described this Important-severity Elevation of Privilege issue as a variant of CVE-2026-70307. Sophos customers have a relevant protection in place (Exp/2650656-A), and a full patch fromCVE-2026-70315CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317CVE-2026-70317CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317

People

Vendors

Products

.NET.NET: 12AccessAccess: 5App InstallerApp Installer: 1Application Insights ProfilerApplication Insights Profiler: 1AzureAzure: 11Azure SQLAzure SQL: 2ColdFusionpatched in advance of Tuesday. There were also 24 updates issued by Adobe, affecting Commerce and ColdFusion.Commercewith everything patched in advance of Tuesday. There were also 24 updates issued by Adobe, affecting Commerce and ColdFusion.Copilotvulnerabilities affecting 10 families have already been mitigated, and a twentieth (CVE-2026-24301, a Copilot Web issue) was handled several days later. The average CVSS Base score for those 20 is 9.3, with threeDefenderCVE-2026-69414 – Microsoft Defender Elevation of Privilege VulnerabilityDynamics 365Dynamics 365: 3Edgein the month, but as these are Windows-related we’re simply rolling them into the main patch count. As for Edge, there were just 42 advisories (all but two issued by Chrome, not Microsoft), with everything patched inEndpoint IPSor even this month’s Preview Pane haul, but exploit-detected is exploit-detected. Sophos Intercept X / Endpoint IPS and XGS Firewall both detect attempts against it as Exp/2668820-A.ExcelExcel: 25ExchangeExchange: 7Google Chromerolling them into the main patch count. As for Edge, there were just 42 advisories (all but two issued by Chrome, not Microsoft), with everything patched in advance of Tuesday. There were also 24 updates issued byMicrosoft 365topped the sheer-volume leaderboard for the second month, racking up 45 finds, all in 365 or Office (or both), 10 of Critical severity. For those who follow such things, there’s an interestingMicrosoft SharePointSharePoint: 30Microsoft TeamsTeams: 6Microsoft Windowsis; CVE-2026-68820 is an Important-severity Elevation of Privilege issue affecting most versions of Windows.) Eighty have a CVSS Base score of 8.0 or higher. Just one was publicly disclosed (but not yet exploited)MMPCMMPC: 2Officetopped the sheer-volume leaderboard for the second month, racking up 45 finds, all in 365 or Office (or both), 10 of Critical severity. For those who follow such things, there’s an interesting divideOneDriveOneDrive: 1OutlookOutlook: 3Planetary ComputerPlanetary Computer: 1Planetary Computer ProCVE-2026-63508 -- Microsoft Planetary Computer Pro Elevation of Privilege VulnerabilityPower AppsPower Apps: 1Power BIPower BI: 1PowerPointPowerPoint: 1PowerShellOnce again we have a lot of multiple-finder vulnerabilities; CVE-2026-58612, an Important-severity PowerShell bug, leads the pack with 17 credited discoverers from around the globe. Anonymous is of course thePurviewPurview: 1Sophos Intercept Xbugs or even this month’s Preview Pane haul, but exploit-detected is exploit-detected. Sophos Intercept X / Endpoint IPS and XGS Firewall both detect attempts against it as Exp/2668820-A.Visual StudioVisual Studio: 18Win App Client /DesktopWin App Client /Desktop: 2WordWord: 16XGS FirewallPreview Pane haul, but exploit-detected is exploit-detected. Sophos Intercept X / Endpoint IPS and XGS Firewall both detect attempts against it as Exp/2668820-A.

Related Articles