# Microsoft August Patch Tuesday releases 421 CVEs, two zero‑days

**Published:** 2026-08-12T04:38:37.557Z  
**Topic:** Microsoft  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/0a43b874-ef8a-4f6c-8914-3b47bcff1223

Microsoft’s August Patch Tuesday fixes 421 vulnerabilities, including two zero‑day exploits, highlighting the growing AI‑driven update volume and priority

Microsoft released patches for 421 unique CVEs on August Patch Tuesday, a volume only slightly lower than July’s record‑breaking 622 fixes, and it includes two zero‑day flaws actively exploited in the wild [1]. The sheer number forces security teams to prioritize, especially as Microsoft leans on AI to uncover more hidden bugs [2].

| At a glance | |
|---|---|
| CVEs addressed | 421 |
| Zero‑day bugs | 2 (CVE‑2026‑68820, CVE‑2026‑62832) |
| Critical severity | 44 |
| Windows‑only CVEs | 236 (covered by cumulative update) |

## Scale and AI‑driven discovery  
Microsoft’s August update marks the second month of “mega‑updates,” a trend the company warned could become the norm as it expands AI‑based code scanning [1]. July’s patch tackled 622 CVEs, while June’s was under 200, showing a rapid escalation in discovered vulnerabilities [2]. Of the 421 CVEs this month, 236 affect Windows and 98 affect Office, both largely covered by cumulative updates [1][2]. The AI push is credited for surfacing long‑standing flaws, turning what were once hidden issues into publicly disclosed patches.

## Highest‑priority zero‑days  
The most urgent flaw, CVE‑2026‑68820, is an elevation‑of‑privilege (EoP) bug in the Windows Ancillary Function Driver for WinSock (afd.sys) that attackers are already exploiting. It lets a locally authenticated user gain SYSTEM‑level rights without user interaction, making it a broad target because the driver is present on most Windows installations [1][2]. The second zero‑day, CVE‑2026‑62832, affects the Windows User Profile Service and, while not yet seen in the wild, is deemed likely to be exploited due to its ability to let a low‑privilege attacker load another user’s registry hive and elevate privileges [1][2].

Both vulnerabilities sit alongside a raft of critical issues across Microsoft’s cloud stack, including a CVSS‑10 Azure SQL Database EoP bug and multiple 9.8‑9.9 rated flaws in Azure Active Directory, Entra Provisioning Service, and the 365 Admin Center [2]. Yet only the afd.sys zero‑day was confirmed under active attack at the time of release, underscoring the importance of triaging patches beyond raw counts.

## What to watch
- **Patch rollout cadence** – Monitor Microsoft’s next Patch Tuesday for whether the AI‑driven volume stabilizes or continues to climb.  
- **Zero‑day exploitation** – Track any emerging evidence of active exploitation for CVE‑2026‑62832 and other high‑severity cloud bugs.  
- **Enterprise response** – Watch for statements from large IT organizations on how they adjust patch‑management processes to handle the growing update load.

The August release confirms that AI‑enhanced vulnerability discovery is reshaping Microsoft’s security update rhythm, turning volume into a new operational challenge for defenders who must now sift through hundreds of fixes to protect critical assets.

## Sources
1. Darkreading — [Microsoft's Patch Tuesday Deluge Continues With August Updates](https://www.darkreading.com/application-security/microsofts-patch-tuesday-deluge-continues)
2. Redmondmag.com — [Microsoft's August Patch Tuesday Keeps the Mega-Update Trend Going](https://redmondmag.com/articles/2026/08/11/microsoft-august-patch-tuesday.aspx)

---
Cite as: TrendWatcher, "Microsoft August Patch Tuesday releases 421 CVEs, two zero‑days", https://www.trendwatcher.in/article/0a43b874-ef8a-4f6c-8914-3b47bcff1223
