[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fjdVsHX6tVkMiM_S-enqguwEiksF7Sng5bH34GqOsfvs":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"0efc9a7b-8548-4f9b-a556-8b0b7c7c787f","Microsoft Patch Tuesday, August 2026 Security Update Review","microsoft-patch-tuesday-august-2026-security-update-review-d48fbb","The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security. Microsoft Patch Tuesday for August 2026 This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities. In this month’s updates, Microsoft has addressed three zero-day vulnerabilities: two publicly disclosed and one exploited in the wild. Microsoft […]","Microsoft's August 2026 Patch Tuesday release tackles 421 vulnerabilities across its product suite, with 62 critical and 357 important severity flaws. Notably, three zero-day vulnerabilities are patched: two publicly disclosed and one actively exploited in the wild. The updates cover critical areas like Windows HTTP.sys, Hyper-V, NTFS, and include fixes for Azure services, GitHub Copilot, and Visual Studio Code.","Microsoft August 2026 Patch Tuesday addresses 421 vulnerabilities, including 3 zero-days.","Table of ContentsMicrosoft Patch Tuesday forAugust2026Zero-day Vulnerabilities Patched inAugustPatch Tuesday EditionCritical Severity Vulnerabilities Patched inAugustPatch Tuesday EditionOther Microsoft Vulnerability HighlightsMicrosoft Release SummaryQualys Monthly Webinar Series The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security. Microsoft Patch Tuesday for August 2026 This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities. In this month’s updates, Microsoft has addressed three zero-day vulnerabilities: two publicly disclosed and one exploited in the wild. Microsoft has not addressed any vulnerabilities in Microsoft Edge (Chromium-based) in this month’s update. Microsoft Patch Tuesday, August edition, includes updates for vulnerabilities in Windows HTTP.sys, Windows Hyper-V, Windows NTFS, Desktop Window Manager, Dynamics Business Central, GitHub Copilot and Visual Studio Code, Microsoft Exchange Server, and more. This month’s release includes fixes for several high-severity issues that could potentially enable remote code execution, privilege escalation, or denial-of-service attacks. As always, timely patch deployment is crucial to reduce exposure and ensure systems remain resilient against exploitation attempts. The August 2026 Microsoft vulnerabilities are classified as follows: Vulnerability Category Quantity Severities Spoofing Vulnerability 20 Critical: 3Important: 17 Denial of Service Vulnerability 12 Important: 12 Elevation of Privilege Vulnerability 178 Critical: 19Important: 159 Information Disclosure Vulnerability 84 Important: 84 Remote Code Execution Vulnerability 109 Critical: 39Important: 70 Security Feature Bypass Vulnerability 11 Important: 11 Zero-day Vulnerabilities Patched in August Patch Tuesday Edition CVE-2026-72971: Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability This is a link following flaw that may allow an authenticated attacker to perform tampering locally. CVE-2026-62832: Windows User Profile Service Elevation of Privilege Vulnerability This is a link following flaw that may allow an authenticated attacker to elevate privileges locally. Upon successful exploitation, this vulnerability may allow an attacker to gain ADMINISTRATOR privileges. CVE-2026-68820: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability The use-after-free flaw in the Windows Ancillary Function Driver for WinSock may allow an authenticated attacker to elevate privileges locally. Successful exploitation of the vulnerability may allow an attacker to gain SYSTEM privileges. Critical Severity Vulnerabilities Patched in August Patch Tuesday Edition CVE-2026-49163: Application Insights Profiler Elevation of Privilege Vulnerability This is a path traversal flaw that may allow an authenticated attacker to elevate privileges over a network. CVE-2026-50481: Azure Active Directory Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges over a network. CVE-2026-68823: Azure Confidential Ledger Remote Code Execution Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to execute code over a network. CVE-2026-62869: Azure Entra ID Spoofing Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to perform spoofing over a network. CVE-2026-56161: Azure Logic Apps Information Disclosure Vulnerability Microsoft has not provided any information about the vulnerability. CVE-2026-50515: Azure Service Bus Remote Code Execution Vulnerability This is a deserialization of untrusted data that may allow an authenticated attacker to execute code over a network. CVE-2026-63522: Azure SQL Database Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges over a network. CVE-2026-56162: Azure SQL Database Elevation of Privilege Vulnerability This is an improper authentication in Azure SQL Database that may allow an unauthenticated attacker to elevate privileges over a network. CVE-2026-62836: Azure SQL Managed Instance Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an unauthenticated attacker to elevate privileges over a network. CVE-2026-62830: Azure SRE Agent Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges over a network. CVE-2026-62873: Microsoft 365 Admin Center Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges over a network. CVE-2026-71331: Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability An integer overflow flaw that may allow an unauthenticated attacker to execute code over a network. CVE-2026-66802: Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability A race condition flaw that may allow an unauthenticated attacker to execute code over a network. CVE-2026-50516: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability A missing authentication flaw that may allow an unauthenticated attacker to elevate privileges over a network. CVE-2026-59115: Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges over a network. CVE-2026-62911: Microsoft Exchange Server Elevation of Privilege Vulnerability Successful exploitation of the vulnerability may allow an authenticated attacker to elevate privileges over a network. CVE-2026-63515: Microsoft Office Remote Code Execution Vulnerability An out-of-bounds read flaw that may allow an unauthenticated attacker to execute code locally. CVE-2026-63513: Microsoft Office Graphics Component Remote Code Execution Vulnerability This is a heap-based buffer overflow flaw that that may allow an unauthenticated attacker to execute code locally. CVE-2026-64910: Microsoft Office Remote Code Execution Vulnerability An untrusted pointer dereference flaw that may allow an unauthenticated attacker to execute code locally. CVE-2026-64909: Microsoft Office Remote Code Execution Vulnerability An integer underflow flaw that may allow an unauthenticated attacker to execute code over a network. CVE-2026-63532, CVE-2026-64903, & CVE-2026-64911: Microsoft Office Remote Code Execution Vulnerability An integer overflow flaw that may allow an unauthenticated attacker to execute code locally. CVE-2026-64898 & CVE-2026-70130: Microsoft Office Remote Code Execution Vulnerability A heap-based buffer overflow flaw that may allow an unauthenticated attacker to execute code locally. CVE-2026-66807 & CVE-2026-63526: Microsoft Office Graphics Component Remote Code Execution Vulnerability A stack-based buffer overflow flaw that may allow an unauthenticated attacker to execute code locally. CVE-2026-62815: Microsoft QUIC Remote Code Execution Vulnerability A use-after-free flaw that may allow an unauthenticated attacker to execute code over a network. CVE-2026-62816: Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability A heap-based buffer overflow flaw that may allow an unauthenticated attacker to execute code over an adjacent network. CVE-2026-62817: Windows DNS Server Remote Code Execution Vulnerability An out-of-bounds write flaw in Windows DNS that may allow an unauthenticated attacker to execute code over an adjacent network. CVE-2026-62818: Windows Active Directory Certificate Services (AD CS) Remote Code Executi","https:\u002F\u002Fblog.qualys.com\u002Fvulnerabilities-threat-research\u002Fpatch-tuesday\u002F2026\u002F08\u002F11\u002Fmicrosoft-patch-tuesday-august-2026-security-update-review","https:\u002F\u002Fik.imagekit.io\u002Fqualys\u002Fwp-content\u002Fuploads\u002F2026\u002F08\u002FMicrosoft-Patch-Tuesday-Aug-2026-1.png","2026-08-11T21:55:19+00:00","2026-08-11T22:00:29.934831+00:00",9,[18,21,24,26,28,30],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"Windows HTTP.sys","product",{"name":25,"type":23},"Windows Hyper-V",{"name":27,"type":23},"Windows NTFS",{"name":29,"type":23},"Dynamics Business Central",{"name":31,"type":23},"GitHub Copilot","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,43,45],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"574f766a-fb3f-487c-8d2c-0720ae75471b","Zero-day","zero-day",{"category":44},{"id":32,"icon":34,"name":35,"slug":36},{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55,58,61,64,67,70,73,76],{"type":52,"value":53,"context":54},"cve","CVE-2026-72971","Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability",{"type":52,"value":56,"context":57},"CVE-2026-62832","Windows User Profile Service Elevation of Privilege Vulnerability",{"type":52,"value":59,"context":60},"CVE-2026-68820","Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",{"type":52,"value":62,"context":63},"CVE-2026-49163","Application Insights Profiler Elevation of Privilege Vulnerability",{"type":52,"value":65,"context":66},"CVE-2026-50481","Azure Active Directory Elevation of Privilege Vulnerability",{"type":52,"value":68,"context":69},"CVE-2026-68823","Azure Confidential Ledger Remote Code Execution Vulnerability",{"type":52,"value":71,"context":72},"CVE-2026-62869","Azure Entra ID Spoofing Vulnerability",{"type":52,"value":74,"context":75},"CVE-2026-56161","Azure Logic Apps Information Disclosure Vulnerability",{"type":52,"value":77,"context":78},"CVE-2026-50515","Azure Service Bus Remote Code Execution Vulnerability"]