Microsoft August 2026 Patch Tuesday Released:​
421 CVEs with Windows and Office Focus

Stay ahead of critical vulnerabilities with our breakdown of this month's Microsoft security patches.

Release Date: Tuesday, August 12, 2026
Release Time: 10:00 AM PST / 1:00 PM EST / 6:00 PM UTC
Status: Released
Last Updated: August 12, 2026

Executive Summary: 421 CVEs Released with Active Exploitation Detected

Microsoft has released its August 2026 Patch Tuesday security updates, addressing 421 unique Microsoft CVEs. This release is smaller than July's record-breaking 621 CVEs but still represents a substantial monthly security update requiring systematic patch deployment across enterprise infrastructure.

Critical Alert:

  • 421 total Microsoft CVEs addressed

  • 2 notable vulnerabilities requiring immediate attention

  • 1 vulnerability with exploitation detected (CVE-2026-68820)

  • 1 publicly known vulnerability (CVE-2026-62832)

  • 236 Windows vulnerabilities (56% of total release)

  • 98 Office vulnerabilities (23.3% of total release)

  • 2 additional non-Microsoft CVEs republished (Windows TPM)

Immediate Actions Required:

  • Deploy CVE-2026-68820 (Windows Ancillary Function Driver EoP) within 24-48 hours (exploitation detected)

  • Deploy CVE-2026-62832 (Windows User Profile Service EoP) within 48-72 hours (publicly known)

  • Deploy remaining Windows vulnerabilities (236 CVEs) within 1-2 weeks

  • Deploy Office patches (98 CVEs) within 1-2 weeks

  • Test SharePoint patches (30 CVEs) in dedicated environments

  • Verify Windows TPM updates (CVE-2026-6726, CVE-2026-6727) on affected systems

August 2026 Release: Detailed Breakdown

Total CVE Count: 421 Microsoft CVEs

August's 421 CVEs represent a moderate release compared to July's record 621 CVEs but significantly above the pre-2026 historical average of 60-90 CVEs per month. This confirms that 2026 has established a new baseline of sustained high-volume security releases.

Comparison to 2026 Releases:

  • January 2026: 112 CVEs
  • February 2026: 59 CVEs
  • March 2026: 83 CVEs
  • April 2026: 165+ CVEs
  • May 2026: 118 CVEs
  • June 2026: 200 CVEs
  • July 2026: 621 CVEs
  • August 2026: 421 CVEs (3.8x increase over pre-2026 baseline)

Vulnerability Distribution by Product

Microsoft organized August's 421 CVEs across the following product categories:

Windows: 236 CVEs (56.1%)

  • Windows 10 and Windows 11 client operating systems
  • Windows Server 2008 R2 through 2025
  • Windows kernel and system components
  • Graphics, networking, storage components
  • Remote Desktop and authentication services

Office: 98 CVEs (23.3%)

  • Microsoft Office 2021, 2019, 2016
  • Microsoft 365 Apps for Enterprise
  • Microsoft Excel, Word, PowerPoint, Outlook
  • Office 2016 requires individual updates (18 distinct updates)
  • Current Office versions use cumulative updates (11 distinct updates)

SharePoint Server: 30 CVEs (7.1%)

  • SharePoint Server 2016, 2019 on-premises
  • Hybrid configurations with Microsoft 365
  • Document management and collaboration features
  • Cumulative update (3 distinct updates)

Developer Tools: 26 CVEs (6.2%)

  • Visual Studio 2022, 2019
  • .NET Framework and .NET Core
  • Azure DevOps and development services
  • 36 distinct cumulative updates

Azure: 17 CVEs (4.0%)

  • Azure cloud services (15 distinct individual updates)
  • Azure infrastructure and platform components
  • Cloud service security fixes

Exchange Server: 7 CVEs (1.7%)

  • Exchange Server 2019 and 2016
  • Exchange Server Subscription Edition (RTM)
  • Email and messaging security fixes
  • 4 distinct cumulative updates

Defender: 1 CVE (0.2%)

  • Windows Defender or related security components
  • 1 distinct cumulative update

Other: 6 CVEs (1.4%)

  • Miscellaneous components and services
  • 4 distinct individual updates

Notable CVEs and Exploitation Status

August 2026 release includes two vulnerabilities of particular note:

CVE-2026-68820: Windows Ancillary Function Driver for WinSock Elevation of Privilege

Severity: High
Exploitation Status: Exploitation Detected (actively exploited in the wild)
Component: Windows Ancillary Function Driver for WinSock (AFD.sys)
Impact: Elevation of Privilege allowing local attackers to escalate from standard user to SYSTEM privileges

Critical Importance:

The detection of active exploitation makes this vulnerability an emergency priority. Organizations using systems where this vulnerability can be exploited must deploy the patch within 24-48 hours.

Typical Attack Chain:

  1. Attacker gains initial system access (phishing, malware, compromised application)
  2. Code executes with user-level privileges
  3. Attacker exploits CVE-2026-68820 to escalate to SYSTEM privileges
  4. Attacker disables security controls and establishes persistence
  5. Attacker moves laterally through network

Deployment Priority: CRITICAL (24-48 hour deployment window)

Monitoring: Organizations should monitor for exploitation attempts targeting AFD.sys driver issues in event logs and endpoint detection systems.

CVE-2026-62832: Windows User Profile Service Elevation of Privilege

Severity: High
Exploitation Status: Publicly Known (vulnerability details available before patch)
Component: Windows User Profile Service
Impact: Elevation of Privilege affecting user profile management and authentication

Importance:

Public disclosure of this vulnerability details before the patch increases exploitation risk. Systems must be patched within 48-72 hours to minimize exposure window.

Deployment Priority: HIGH (48-72 hour deployment window)

Non-Microsoft CVEs Republished

August release includes 2 non-Microsoft CVEs republished by Microsoft:

CVE-2026-6726: Windows TPM Vulnerability

  • CNA: MITRE
  • Category: Windows Trusted Platform Module (TPM)
  • FAQs: Available
  • Workarounds: No workarounds available
  • Mitigations: No mitigations available (patch required)

CVE-2026-6727: Windows TPM Vulnerability

  • CNA: MITRE
  • Category: Windows Trusted Platform Module (TPM)
  • FAQs: Available
  • Workarounds: No workarounds available
  • Mitigations: No mitigations available (patch required)

Impact: These TPM vulnerabilities affect systems using Trusted Platform Module for security, device encryption, and authentication. Organizations should prioritize patching systems with TPM-dependent security features.

Affected Products and Components: Detailed List

Windows Operating Systems (236 CVEs)

Client Operating Systems:

  • Windows 11 (all versions: 21H2, 22H2, 23H2, 24H2, 25H2, 26H1)
  • Windows 10 (ESU-enrolled systems: 22H2, 21H2)

Server Operating Systems:

  • Windows Server 2025
  • Windows Server 2022
  • Windows Server 2019
  • Windows Server 2016
  • Windows Server 2012 R2
  • Windows Server 2012
  • Windows Server 2008 R2 (requires Extended Security Update)

Core Components (236 CVEs covering):

  • Windows Kernel and kernel-mode drivers
  • Graphics components (GDI+, DirectX)
  • Networking and communications protocols
  • Remote Desktop Services
  • Windows Authentication and Kerberos
  • Windows Print Spooler
  • Storage and file systems
  • Event logging and monitoring

Office Applications (98 CVEs)

Affected Office Versions:

  • Microsoft Office 2021
  • Microsoft Office 2019
  • Microsoft Office 2016 (requires individual updates)
  • Microsoft 365 Apps for Enterprise

Components Affected:

  • Microsoft Excel (remote code execution and information disclosure flaws)
  • Microsoft Word (document processing vulnerabilities)
  • Microsoft PowerPoint (presentation handling issues)
  • Microsoft Outlook (email and calendar vulnerabilities)
  • Microsoft Access (database application flaws)

SharePoint Server (30 CVEs)

Affected Versions:

  • SharePoint Server 2019
  • SharePoint Server 2016

Impact Areas:

  • Document management and retrieval
  • Web content management
  • Collaborative features
  • Search functionality
  • Authentication and access control

Developer Tools (26 CVEs)

Visual Studio:

  • Visual Studio 2022
  • Visual Studio 2019

Development Platforms:

  • .NET Framework 4.8, 4.7.2
  • .NET 10.0, 9.0

Services:

  • Azure DevOps Server
  • GitHub integration components

Additional Products

Azure Services (17 CVEs): Cloud infrastructure and platform components
Exchange Server (7 CVEs): Email and messaging services
Defender (1 CVE): Windows Defender and security components
Other (6 CVEs): Miscellaneous components

Deployment Strategy: August 12-26

Critical Priority (24-48 Hours): CVE-2026-68820

Immediate Actions:

  1. Hour 0-4: Download and secure AFD.sys driver patch
  2. Hour 4-12: Deploy to pilot group (5-10% of infrastructure)
  3. Hour 12-24: Wave 1 production deployment (non-critical systems)
  4. Hour 24-48: Wave 2 production deployment (all remaining systems)

Testing Checklist:

  • [ ] System boots successfully post-patch
  • [ ] Network connectivity functional
  • [ ] No performance degradation
  • [ ] Applications launch normally
  • [ ] No driver conflicts

High Priority (48-72 Hours): CVE-2026-62832 and TPM CVEs

Deployment Timeline:

  1. August 12-13: Pilot testing of User Profile Service and TPM patches
  2. August 13-14: Initial production deployment (non-critical systems)
  3. August 14-15: Broader production deployment (important systems)
  4. August 15: Complete deployment to all systems

Important Priority (1-2 Weeks): Windows and Office Patches

Phased Deployment:

Days 1-4 (August 12-15): Windows critical patches

  • Deploy remaining high-priority Windows patches
  • Test for driver compatibility
  • Monitor system stability

Days 5-7 (August 16-18): Office patches

  • Deploy 98 Office CVE patches
  • Test Excel, Word, PowerPoint, Outlook functionality
  • Verify document compatibility

Days 8-14 (August 19-25): SharePoint and remaining patches

  • Deploy SharePoint patches to dedicated test environment first
  • Verify document access and sharing
  • Deploy Azure, Developer Tools, Exchange patches
  • Complete all Important-severity patches

Monitoring and Validation (August 26+)

  • Verify 100% patch deployment compliance
  • Conduct compliance scans
  • Address any missed systems
  • Prepare for September Patch Tuesday

Known Issues and Important Updates

Windows Server 2025 Hotpatch Known Issue

KB Article: 5120228
Applies To: Windows Server 2025
Status: Known issue documented

Organizations running Windows Server 2025 with Hotpatching enabled should review KB5120228 for any compatibility issues.

Exchange Server Updates

Known Issues:

  • KB 5121573: Exchange Server Subscription Edition RTM
  • KB 5121574: Exchange Server 2019 CU15
  • KB 5121575: Exchange Server 2019 CU14
  • KB 5121576: Exchange Server 2016 CU23

Organizations running Exchange Server should review applicable KB articles before deployment.

Important Notes

Windows 10 and Windows 11 Updates:

  • All updates are cumulative (include all previous security fixes)
  • Available via Microsoft Update Catalog
  • Include non-security quality updates alongside security patches

Windows Server 2008 R2 and 2008:

  • Extended Security Update (ESU) required for continued security support
  • See KB4522133 for purchasing and enrollment information

Hotpatching Feature:

  • Now generally available for Windows Server Azure Edition VMs
  • See official Hotpatching documentation for deployment guidance

Servicing Stack Updates:

  • Important to install latest servicing stack updates
  • See ADV990001 for complete list by operating system

Testing Checklist

Before deploying August patches to production, validate:

System Functionality:

  • [ ] Windows boots successfully
  • [ ] Network connectivity functional
  • [ ] Authentication to domain controllers working
  • [ ] Remote Desktop Services operational
  • [ ] Print services functional
  • [ ] File sharing operational

Windows Stability:

  • [ ] No driver conflicts or errors
  • [ ] Graphics rendering normal
  • [ ] No networking issues
  • [ ] Storage and file systems functioning

Office Functionality:

  • [ ] Excel opens and calculates normally
  • [ ] Word creates and edits documents
  • [ ] PowerPoint presentations display correctly
  • [ ] Outlook connects to mail servers
  • [ ] No document compatibility issues

SharePoint (if applicable):

  • [ ] Document library access working
  • [ ] Document uploading functional
  • [ ] Search functionality operational
  • [ ] User permissions intact

Performance:

  • [ ] Boot times acceptable
  • [ ] Application launch times normal
  • [ ] No unusual CPU/memory consumption
  • [ ] Network throughput satisfactory

Security:

  • [ ] Windows Defender operational
  • [ ] Firewall rules intact
  • [ ] BitLocker encryption maintained
  • [ ] Endpoint protection functioning

Resources and Support

Microsoft Official Resources

Vulnerability Intelligence

Zecurit Resources

Conclusion: August 2026 Release Demands Systematic Deployment

August 2026 Patch Tuesday delivers 421 CVEs requiring systematic deployment across enterprise infrastructure. The active exploitation of CVE-2026-68820 and public disclosure of CVE-2026-62832 create emergency deployment requirements for elevation of privilege vulnerabilities.

Critical Action Items:

  1. Deploy CVE-2026-68820 within 24-48 hours (active exploitation detected)
  2. Deploy CVE-2026-62832 within 48-72 hours (publicly disclosed)
  3. Deploy Windows TPM patches for affected systems
  4. Deploy remaining 236 Windows patches within 1-2 weeks
  5. Deploy 98 Office patches within 1-2 weeks
  6. Test SharePoint patches in dedicated environments
  7. Verify patch deployment compliance across all systems

The Bottom Line:

August 2026 represents a substantial monthly security release with 421 CVEs. The active exploitation of one vulnerability and public disclosure of another demand rapid deployment. Systematic testing and phased deployment of the remaining patches will ensure comprehensive security coverage while minimizing operational disruption.

Organizations should activate rapid deployment procedures immediately, prioritizing the two notable vulnerabilities while maintaining systematic deployment of the remaining 419 CVEs over the following two weeks.


For comprehensive endpoint management and automated patch deployment with vulnerability scanning and compliance reporting, explore Zecurit Endpoint Manager.

Deployment must begin immediately. CVE-2026-68820 shows active exploitation. Deploy within 24 hours.

Patch Tuesday: CVE Details

Below is a detailed list of the security patches and CVEs released in this month's Patch. This information is fetched directly from the Microsoft Security Response Center (MSRC) to help you stay protected with the latest patches.

What is Patch Tuesday and Why is it so Important?

Introduced by Microsoft in 2003, Patch Tuesday was created to bring order to the chaotic world of software updates. Before this schedule, updates were released sporadically, making it difficult for IT teams to plan their patching efforts.

Today, the predictable monthly schedule allows administrators to prepare for the deployment of these patches. However, the importance of Patch Tuesday goes beyond simple scheduling:

  • Proactive Vulnerability Management: It is Microsoft's primary mechanism for addressing publicly known Common Vulnerabilities and Exposures (CVEs) in its products.

  • Averting Cyberattacks: Timely patching is the most effective way to prevent cybercriminals from exploiting known weaknesses. For every patch Microsoft releases, attackers race to reverse-engineer the update to find the underlying vulnerability and develop an exploit for unpatched systems—a phenomenon often referred to as "Exploit Wednesday."

  • System Stability: Beyond security, these updates often contain important bug fixes and performance enhancements that ensure your systems run smoothly.

Patch Management Best Practices for Businesses

Effectively handling Patch Tuesday updates is a core responsibility for any IT team. Simply installing the patches isn't enough; a well-defined process is needed to minimize risk and prevent system downtime.

Here are some best practices for managing your patching cycle:

  1. Prioritize Patches: Not all patches are created equal. Focus on deploying updates with a "Critical" or "Important" severity rating first, as these address the most severe vulnerabilities.

  2. Test Before Deployment: Never roll out patches to your entire organization without testing them first. Use a staging or lab environment that mirrors your production systems to check for any compatibility issues or bugs.

  3. Automate the Process: Tools like Windows Server Update Services (WSUS) and Microsoft Endpoint Configuration Manager (SCCM) are indispensable for automating the deployment of patches. Automation saves time, reduces human error, and ensures consistency across your network.

  4. Monitor and Verify: After deployment, actively monitor systems to ensure the patches were installed correctly and did not cause any unexpected issues. A rollback plan should be in place to quickly revert any problematic updates.

  5. Stay Informed: Follow official Microsoft security channels and industry news to stay up-to-date on any out-of-band updates (critical patches released outside of the normal schedule) or known issues with the monthly patches.

Understanding CVEs: What to Look For

Patch Tuesday updates are tied to specific CVEs. A CVE (Common Vulnerabilities and Exposures) is a unique ID number assigned to a publicly known security flaw. Each CVE entry provides a brief description of the vulnerability, allowing security professionals to track and prioritize fixes.

When reviewing our monthly list of CVEs, pay close attention to:

  • Severity Rating: Microsoft assigns a severity rating (Critical, Important, Moderate, Low) to each vulnerability. Critical vulnerabilities, which could allow remote code execution without user interaction, should be your highest priority.

  • Exploitability: The "Exploited" status indicates if a vulnerability is being actively targeted by attackers. Patches for these CVEs must be applied immediately.

Patch Tuesday is more than just a monthly event; it is the cornerstone of modern vulnerability management for anyone using Microsoft products. By understanding what it is, embracing best practices, and staying informed about the latest CVEs, you can strengthen your security posture and protect your organization from a constantly evolving threat landscape.

Frequently Asked Questions (FAQs)

  • What is Patch Tuesday?

    Patch Tuesday is the second Tuesday of each month when Microsoft releases its regular updates for Windows operating systems and other Microsoft products. These updates typically include security patches, bug fixes, and sometimes feature improvements.

  • Why is Patch Tuesday important?

    Patch Tuesday is crucial for maintaining the security and stability of systems. The updates often address vulnerabilities that could be exploited by attackers, and keeping systems up to date helps protect against these risks.

  • How do I know when a new Patch Tuesday update is released?

    Microsoft releases Patch Tuesday updates on their website and through Windows Update. For detailed patch notes, you can refer to Microsoft's Security Update Guide or subscribe to update notifications from your device or trusted sources like security blogs.

  • Can I manually install Patch Tuesday updates?

    Yes, you can manually download and install updates through Windows Update, or directly from the Microsoft Update Catalog website, which offers patches for individual downloads.

  • Do I need to install every update?

    It’s highly recommended to install all security updates to ensure your system remains protected from known vulnerabilities. However, non-security updates or feature updates might be optional based on your needs.

  • What happens if I miss a Patch Tuesday update?

    If you miss a Patch Tuesday update, it’s important to install the updates as soon as possible to avoid potential security risks. Microsoft allows you to download and install any missed updates through Windows Update.

  • How do I manage Patch Tuesday updates on multiple systems?

    For businesses or IT administrators, you can use Windows Server Update Services (WSUS), System Center Configuration Manager (SCCM), or third-party patch management tools to schedule, approve, and distribute updates across multiple systems.

  • Are all updates released on Patch Tuesday critical?

    Not all updates are critical. Patch Tuesday updates include a range of fixes, from critical security patches to optional non-security updates. It’s important to assess which updates are most relevant to your environment.

  • What is the impact of not applying Patch Tuesday updates?

    Failing to apply updates can leave your system vulnerable to exploits and attacks. Many of the updates address critical security flaws that cybercriminals may target, so staying updated is vital for system security.

Important Links

Microsoft Security Updates Guide
This is the primary source for information on Microsoft's security updates. It includes details on the vulnerabilities addressed, affected products, and mitigation guidance.
Read more
Microsoft Security Response Center
This blog shares insights on current security threats and Microsoft's responses, detailing specific vulnerabilities and their potential impacts.
Read more
CVE details
The CVE database offers detailed insights on vulnerabilities, including severity, descriptions, and their potential impacts on security.
Read more
Security advisories
Microsoft publishes security advisories for critical vulnerabilities, detailing the issue, its impact, and recommended mitigation steps.
Read more
Secret Link