Microsoft’s August Patch Tuesday Update Fixes 400 Vulnerabilities, Including Three Zero-Day Flaws
Today, Microsoft released its highly anticipated August Patch Tuesday update, addressing a staggering 400 security vulnerabilities across its software products. Among these critical flaws are three zero-day vulnerabilities, with one already being actively exploited in attacks and two publicly disclosed.
The sheer scale of this month’s patch release is impressive, but it’s not without significance. This marks the third consecutive month that Microsoft has issued over 300 patches, a trend attributed to its new AI-powered vulnerability discovery system. While last month saw an astonishing 570 flaws fixed, August’s update still packs a punch with 42 “Critical” vulnerabilities, including 37 remote code execution and 5 elevation of privilege flaws.
So, what exactly is happening here? In plain terms, when Microsoft identifies security vulnerabilities in its products, it must issue patches to fix them before attackers can exploit them. These patches are released on the second Tuesday of every month as part of the Patch Tuesday update cycle. The AI-powered system has undoubtedly increased the number of identified flaws, but it’s also allowing Microsoft to stay one step ahead of potential threats.
Among this month’s most critical fixes are three zero-day vulnerabilities. A zero-day flaw is a previously unknown vulnerability that attackers can exploit before a patch is available. In this case, two of these flaws were publicly disclosed by security researchers, while the third was actively exploited in attacks.
One of these zero-day vulnerabilities, CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock and allows an attacker to gain SYSTEM privileges with no user interaction required. This vulnerability was credited to Moshe Marelus and David Driker from Checkpoint, who discovered it was exploited by North Korean threat actors known as Lazarus in zero-day attacks.
The other publicly disclosed zero-day vulnerability, CVE-2026-62832, affects the Windows User Profile service and allows an attacker to gain administrator privileges. While Microsoft attributed this flaw to an anonymous researcher, details match a previously disclosed vulnerability called “LegacyHive” by security researcher Nightmare Eclipse last month.
It’s essential for users to prioritize these updates and apply them as soon as possible to prevent potential attacks. With the rise of AI-powered vulnerability discovery systems, we can expect even more frequent and critical patches in the future. To stay ahead of threats, it’s crucial to maintain up-to-date software, remain vigilant about patching, and keep a close eye on security research from reputable sources.
Remember, security is an ongoing process that requires continuous effort and attention. By staying informed and taking proactive steps to protect your systems, you can significantly reduce the risk of falling victim to attacks exploiting these vulnerabilities.
Source: Bleeping Computer — 2026-08-11