Stay ahead of critical vulnerabilities with our breakdown of this month's Microsoft security patches.
Release Date: Tuesday, August 12, 2026
Release Time: 10:00 AM PST / 1:00 PM EST / 6:00 PM UTC
Status: Released
Last Updated: August 12, 2026
Microsoft has released its August 2026 Patch Tuesday security updates, addressing 421 unique Microsoft CVEs. This release is smaller than July's record-breaking 621 CVEs but still represents a substantial monthly security update requiring systematic patch deployment across enterprise infrastructure.
Critical Alert:
421 total Microsoft CVEs addressed
2 notable vulnerabilities requiring immediate attention
1 vulnerability with exploitation detected (CVE-2026-68820)
1 publicly known vulnerability (CVE-2026-62832)
236 Windows vulnerabilities (56% of total release)
98 Office vulnerabilities (23.3% of total release)
2 additional non-Microsoft CVEs republished (Windows TPM)
Immediate Actions Required:
Deploy CVE-2026-68820 (Windows Ancillary Function Driver EoP) within 24-48 hours (exploitation detected)
Deploy CVE-2026-62832 (Windows User Profile Service EoP) within 48-72 hours (publicly known)
Deploy remaining Windows vulnerabilities (236 CVEs) within 1-2 weeks
Deploy Office patches (98 CVEs) within 1-2 weeks
Test SharePoint patches (30 CVEs) in dedicated environments
Verify Windows TPM updates (CVE-2026-6726, CVE-2026-6727) on affected systems
August's 421 CVEs represent a moderate release compared to July's record 621 CVEs but significantly above the pre-2026 historical average of 60-90 CVEs per month. This confirms that 2026 has established a new baseline of sustained high-volume security releases.
Comparison to 2026 Releases:
Microsoft organized August's 421 CVEs across the following product categories:
Windows: 236 CVEs (56.1%)
Office: 98 CVEs (23.3%)
SharePoint Server: 30 CVEs (7.1%)
Developer Tools: 26 CVEs (6.2%)
Azure: 17 CVEs (4.0%)
Exchange Server: 7 CVEs (1.7%)
Defender: 1 CVE (0.2%)
Other: 6 CVEs (1.4%)
August 2026 release includes two vulnerabilities of particular note:
Severity: High
Exploitation Status: Exploitation Detected (actively exploited in the wild)
Component: Windows Ancillary Function Driver for WinSock (AFD.sys)
Impact: Elevation of Privilege allowing local attackers to escalate from standard user to SYSTEM privileges
Critical Importance:
The detection of active exploitation makes this vulnerability an emergency priority. Organizations using systems where this vulnerability can be exploited must deploy the patch within 24-48 hours.
Typical Attack Chain:
Deployment Priority: CRITICAL (24-48 hour deployment window)
Monitoring: Organizations should monitor for exploitation attempts targeting AFD.sys driver issues in event logs and endpoint detection systems.
Severity: High
Exploitation Status: Publicly Known (vulnerability details available before patch)
Component: Windows User Profile Service
Impact: Elevation of Privilege affecting user profile management and authentication
Importance:
Public disclosure of this vulnerability details before the patch increases exploitation risk. Systems must be patched within 48-72 hours to minimize exposure window.
Deployment Priority: HIGH (48-72 hour deployment window)
August release includes 2 non-Microsoft CVEs republished by Microsoft:
CVE-2026-6726: Windows TPM Vulnerability
CVE-2026-6727: Windows TPM Vulnerability
Impact: These TPM vulnerabilities affect systems using Trusted Platform Module for security, device encryption, and authentication. Organizations should prioritize patching systems with TPM-dependent security features.
Client Operating Systems:
Server Operating Systems:
Core Components (236 CVEs covering):
Affected Office Versions:
Components Affected:
Affected Versions:
Impact Areas:
Visual Studio:
Development Platforms:
Services:
Azure Services (17 CVEs): Cloud infrastructure and platform components
Exchange Server (7 CVEs): Email and messaging services
Defender (1 CVE): Windows Defender and security components
Other (6 CVEs): Miscellaneous components
Immediate Actions:
Testing Checklist:
Deployment Timeline:
Phased Deployment:
Days 1-4 (August 12-15): Windows critical patches
Days 5-7 (August 16-18): Office patches
Days 8-14 (August 19-25): SharePoint and remaining patches
KB Article: 5120228
Applies To: Windows Server 2025
Status: Known issue documented
Organizations running Windows Server 2025 with Hotpatching enabled should review KB5120228 for any compatibility issues.
Known Issues:
Organizations running Exchange Server should review applicable KB articles before deployment.
Windows 10 and Windows 11 Updates:
Windows Server 2008 R2 and 2008:
Hotpatching Feature:
Servicing Stack Updates:
Before deploying August patches to production, validate:
System Functionality:
Windows Stability:
Office Functionality:
SharePoint (if applicable):
Performance:
Security:
August 2026 Patch Tuesday delivers 421 CVEs requiring systematic deployment across enterprise infrastructure. The active exploitation of CVE-2026-68820 and public disclosure of CVE-2026-62832 create emergency deployment requirements for elevation of privilege vulnerabilities.
Critical Action Items:
The Bottom Line:
August 2026 represents a substantial monthly security release with 421 CVEs. The active exploitation of one vulnerability and public disclosure of another demand rapid deployment. Systematic testing and phased deployment of the remaining patches will ensure comprehensive security coverage while minimizing operational disruption.
Organizations should activate rapid deployment procedures immediately, prioritizing the two notable vulnerabilities while maintaining systematic deployment of the remaining 419 CVEs over the following two weeks.
For comprehensive endpoint management and automated patch deployment with vulnerability scanning and compliance reporting, explore Zecurit Endpoint Manager.
Deployment must begin immediately. CVE-2026-68820 shows active exploitation. Deploy within 24 hours.
Below is a detailed list of the security patches and CVEs released in this month's Patch. This information is fetched directly from the Microsoft Security Response Center (MSRC) to help you stay protected with the latest patches.
Introduced by Microsoft in 2003, Patch Tuesday was created to bring order to the chaotic world of software updates. Before this schedule, updates were released sporadically, making it difficult for IT teams to plan their patching efforts.
Today, the predictable monthly schedule allows administrators to prepare for the deployment of these patches. However, the importance of Patch Tuesday goes beyond simple scheduling:
Proactive Vulnerability Management: It is Microsoft's primary mechanism for addressing publicly known Common Vulnerabilities and Exposures (CVEs) in its products.
Averting Cyberattacks: Timely patching is the most effective way to prevent cybercriminals from exploiting known weaknesses. For every patch Microsoft releases, attackers race to reverse-engineer the update to find the underlying vulnerability and develop an exploit for unpatched systems—a phenomenon often referred to as "Exploit Wednesday."
System Stability: Beyond security, these updates often contain important bug fixes and performance enhancements that ensure your systems run smoothly.
Effectively handling Patch Tuesday updates is a core responsibility for any IT team. Simply installing the patches isn't enough; a well-defined process is needed to minimize risk and prevent system downtime.
Here are some best practices for managing your patching cycle:
Prioritize Patches: Not all patches are created equal. Focus on deploying updates with a "Critical" or "Important" severity rating first, as these address the most severe vulnerabilities.
Test Before Deployment: Never roll out patches to your entire organization without testing them first. Use a staging or lab environment that mirrors your production systems to check for any compatibility issues or bugs.
Automate the Process: Tools like Windows Server Update Services (WSUS) and Microsoft Endpoint Configuration Manager (SCCM) are indispensable for automating the deployment of patches. Automation saves time, reduces human error, and ensures consistency across your network.
Monitor and Verify: After deployment, actively monitor systems to ensure the patches were installed correctly and did not cause any unexpected issues. A rollback plan should be in place to quickly revert any problematic updates.
Stay Informed: Follow official Microsoft security channels and industry news to stay up-to-date on any out-of-band updates (critical patches released outside of the normal schedule) or known issues with the monthly patches.
Patch Tuesday updates are tied to specific CVEs. A CVE (Common Vulnerabilities and Exposures) is a unique ID number assigned to a publicly known security flaw. Each CVE entry provides a brief description of the vulnerability, allowing security professionals to track and prioritize fixes.
When reviewing our monthly list of CVEs, pay close attention to:
Severity Rating: Microsoft assigns a severity rating (Critical, Important, Moderate, Low) to each vulnerability. Critical vulnerabilities, which could allow remote code execution without user interaction, should be your highest priority.
Exploitability: The "Exploited" status indicates if a vulnerability is being actively targeted by attackers. Patches for these CVEs must be applied immediately.
Patch Tuesday is more than just a monthly event; it is the cornerstone of modern vulnerability management for anyone using Microsoft products. By understanding what it is, embracing best practices, and staying informed about the latest CVEs, you can strengthen your security posture and protect your organization from a constantly evolving threat landscape.
Patch Tuesday is the second Tuesday of each month when Microsoft releases its regular updates for Windows operating systems and other Microsoft products. These updates typically include security patches, bug fixes, and sometimes feature improvements.
Patch Tuesday is crucial for maintaining the security and stability of systems. The updates often address vulnerabilities that could be exploited by attackers, and keeping systems up to date helps protect against these risks.
Microsoft releases Patch Tuesday updates on their website and through Windows Update. For detailed patch notes, you can refer to Microsoft's Security Update Guide or subscribe to update notifications from your device or trusted sources like security blogs.
Yes, you can manually download and install updates through Windows Update, or directly from the Microsoft Update Catalog website, which offers patches for individual downloads.
It’s highly recommended to install all security updates to ensure your system remains protected from known vulnerabilities. However, non-security updates or feature updates might be optional based on your needs.
If you miss a Patch Tuesday update, it’s important to install the updates as soon as possible to avoid potential security risks. Microsoft allows you to download and install any missed updates through Windows Update.
For businesses or IT administrators, you can use Windows Server Update Services (WSUS), System Center Configuration Manager (SCCM), or third-party patch management tools to schedule, approve, and distribute updates across multiple systems.
Not all updates are critical. Patch Tuesday updates include a range of fixes, from critical security patches to optional non-security updates. It’s important to assess which updates are most relevant to your environment.
Failing to apply updates can leave your system vulnerable to exploits and attacks. Many of the updates address critical security flaws that cybercriminals may target, so staying updated is vital for system security.