[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fB8lNBZaTXp0ooFR5-z98xBrmVfFn3zOb98DykFiBTRo":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"8bc77bd6-acfd-4d36-ae77-a2056512da33","Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days","microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days-5a84ed","Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. [...]","Microsoft's August 2026 Patch Tuesday addresses a significant 400 vulnerabilities, including three zero-days. One of these zero-days, CVE-2026-68820, was actively exploited by North Korean threat actors Lazarus to deploy their kernel-mode rootkit, FudModule. The other two zero-days, CVE-2026-68820 and another in the Windows User Profile Service, were publicly disclosed.","Microsoft August 2026 Patch Tuesday fixes 400 flaws, including 3 zero-days.","Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days By Lawrence Abrams August 11, 2026 02:08 PM 2 Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities. Patch Tuesday addresses 42 \"Critical\" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege. The approximate number of bugs in each vulnerability category is listed below: 176 Elevation of Privilege Vulnerabilities 11 Security Feature Bypass Vulnerabilities 110 Remote Code Execution Vulnerabilities 86 Information Disclosure Vulnerabilities 12 Denial of Service Vulnerabilities 21 Spoofing Vulnerabilities When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include some flaws in Mariner, Microsoft Teams, Microsoft Azure, Microsoft Entra, Microsoft Office, and Power Apps that were fixed by Microsoft earlier this month. While this Patch Tuesday is not as large as last month's, which fixed 570 flaws, it is still very large compared to the previous month. Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discovery system to identify more security flaws across its software products. To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5121003 & KB5120240 cumulative updates and the Windows 10 KB5120249 extended security update. Microsoft patches 3 zero-days This month's Patch Tuesday fixes three zero-day vulnerabilities, with one exploited in attacks and two publicly disclosed. Microsoft classifies a zero-day flaw as publicly disclosed or actively exploited while no official fix is available. The actively exploited zero-day vulnerabilities addressed during this month's Patch Tuesday are: CVE-2026-68820 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Microsoft has patched an actively exploited vulnerability in the Windows Ancillary Function Driver for WinSock that grants SYSTEM privileges. \"Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally,\" warns Microsoft. \"A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required,\" continued Microsoft. The flaws were credited to Moshe Marelus and David Driker with Checkpoint. In a report released today, Check Point says the flaw was exploited in zero-day attacks by the North Korean threat actors known as Lazarus to deploy malware. \"During the intrusion, the threat actor exploited CVE-2026-68820, a zero-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit,\" said Check Point. Microsoft has not shared any details on how the flaws were exploited. The two publicly disclosed zero-days that was fixed are: CVE-2026-62832 - Windows User Profile Service Elevation of Privilege Vulnerability Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges. \"Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally,\" explains Microsoft. \"An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required,\" continued Microsoft. While Microsoft attributed the flaw to an anonymous researcher, the details match a zero-day vulnerability called \"LegacyHive\" that was disclosed by a security researcher named Nightmare Eclipse last month. Tharros principal vulnerability analyst Will Dormann previously said that non-admin users can exploit LegacyHive to modify the registry hive to launch commands with administrative privileges when the when the admin account logs into a compromised device. CVE-2026-72971 - Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability Microsoft has patched a publicly disclosed elevation of privileges flaw in the Windows User Profile service that provides adminstrator privileges. \"Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally,\" explains Microsoft. \"An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required,\" continued Microsoft. Microsoft has not shared any details on where the flaw was disclosed but attributed the discovery to yhw & txz. Other vendors who released updates or advisories in August 2026 include: Adobe released security updates for vulnerabilities in Coldfusion, Commerce, Lightroom Classic, Content Credentials SDK, and Campaign Classic. Cisco released security updates for numerous products, including Cisco Catalyst SD-WAN, IOS, IOS XE, and ClamAV flaws with public exploits. Metabase released security updates for a critical SQLi flaw that was exploited in data-theft attacks. N-able released security updates for an actively exploited authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. SAP released the August security updates for numerous products, including a 10.0-severity improper authorization flaw in SAP Commerce Cloud (Data Hub Adapter). TP-Link patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could lead to RCE. VMware released security updates for VMware Avi Load Balancer, which include authentication bypasses and remote code execution flaws. The August 2026 Patch Tuesday Security Updates Below is the complete list of resolved vulnerabilities in the August 2026 Patch Tuesday updates, excluding flaws fixed before today. To access the full description of each vulnerability and the systems it affects, you can view the full report here. Tag CVE ID CVE Title Severity .NET CVE-2026-58641 .NET Elevation of Privilege Vulnerability Important .NET CVE-2026-62901 .NET Denial of Service Vulnerability Important .NET CVE-2026-70354 .NET Core Remote Code Execution Vulnerability Important .NET CVE-2026-62899 .NET Security Feature Bypass Vulnerability Important .NET CVE-2026-62902 .NET Information Disclosure Vulnerability Important .NET CVE-2026-62900 .NET Information Disclosure Vulnerability Important .NET CVE-2026-62886 .NET Elevation of Privilege Vulnerability Important .NET CVE-2026-62909 .NET Elevation of Privilege Vulnerability Important .NET CVE-2026-62871 .NET Elevation of Privilege Vulnerability Important .NET Framework CVE-2026-65810 .NET Framework Elevation of Privilege Vulnerability Important .NET Framework CVE-2026-62872 .NET Framework Elevation of Privilege Vulnerability Important .NET Framework CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability Important Active Directory Certificate Services (AD CS) CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Critical AMD Zen CVE-2026-59131 AMD Zen Information Disclosure Vulnerability Important AMD Zen CVE-2026-59130 AMD Zen Information Disclosure Vulnerability Important Application Information Services CVE-2026-61357 Application Informat","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fmicrosoft\u002Fmicrosoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2024\u002F10\u002F08\u002Fpatch_tuesday_microsoft.jpg","2026-08-11T18:08:50+00:00","2026-08-11T20:00:10.105804+00:00",9,[18,21,24],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"Lazarus Group","threat_actor",{"name":25,"type":26},"Windows","product","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,38,43,45],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":27,"icon":29,"name":30,"slug":31},{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[51,55,58],{"type":52,"value":53,"context":54},"cve","CVE-2026-68820","Actively exploited Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",{"type":52,"value":56,"context":57},"CVE-2026-62832","Publicly disclosed Windows User Profile Service Elevation of Privilege Vulnerability",{"type":49,"value":59,"context":60},"FudModule","Kernel-mode rootkit deployed by Lazarus Group"]