Loading article…
Microsoft’s August Patch Tuesday fixes 421 vulnerabilities, including two zero‑day exploits, highlighting the growing AI‑driven update volume and priority
Microsoft released patches for 421 unique CVEs on August Patch Tuesday, a volume only slightly lower than July’s record‑breaking 622 fixes, and it includes two zero‑day flaws actively exploited in the wild [1]. The sheer number forces security teams to prioritize, especially as Microsoft leans on AI to uncover more hidden bugs [2].
| At a glance | |
|---|---|
| CVEs addressed | 421 |
| Zero‑day bugs | 2 (CVE‑2026‑68820, CVE‑2026‑62832) |
| Critical severity | 44 |
| Windows‑only CVEs | 236 (covered by cumulative update) |
Microsoft’s August update marks the second month of “mega‑updates,” a trend the company warned could become the norm as it expands AI‑based code scanning [1]. July’s patch tackled 622 CVEs, while June’s was under 200, showing a rapid escalation in discovered vulnerabilities [2]. Of the 421 CVEs this month, 236 affect Windows and 98 affect Office, both largely covered by cumulative updates [1][2]. The AI push is credited for surfacing long‑standing flaws, turning what were once hidden issues into publicly disclosed patches.
The most urgent flaw, CVE‑2026‑68820, is an elevation‑of‑privilege (EoP) bug in the Windows Ancillary Function Driver for WinSock (afd.sys) that attackers are already exploiting. It lets a locally authenticated user gain SYSTEM‑level rights without user interaction, making it a broad target because the driver is present on most Windows installations [1][2]. The second zero‑day, CVE‑2026‑62832, affects the Windows User Profile Service and, while not yet seen in the wild, is deemed likely to be exploited due to its ability to let a low‑privilege attacker load another user’s registry hive and elevate privileges [1][2].
Both vulnerabilities sit alongside a raft of critical issues across Microsoft’s cloud stack, including a CVSS‑10 Azure SQL Database EoP bug and multiple 9.8‑9.9 rated flaws in Azure Active Directory, Entra Provisioning Service, and the 365 Admin Center [2]. Yet only the afd.sys zero‑day was confirmed under active attack at the time of release, underscoring the importance of triaging patches beyond raw counts.
The August release confirms that AI‑enhanced vulnerability discovery is reshaping Microsoft’s security update rhythm, turning volume into a new operational challenge for defenders who must now sift through hundreds of fixes to protect critical assets.
Coverage is mostly measured — 206 of 206 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Aug 12, 2026 · How we report
Microsoft was founded on April 4, 1975, by Bill Gates and Paul Allen.
The U.S. Department of Justice and 20 states accused Microsoft of illegally maintaining an operating system monopoly by bundling Internet Explorer with Windows.
Microsoft leadership directed engineers to quickly test and deploy the DeepSeek R1 model on Azure AI Foundry and GitHub.