Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today, Microsoft released its August 2026 Patch Tuesday update, addressing a staggering 400 security flaws in its software products. Among these vulnerabilities are three zero-days, with one actively exploited and two publicly disclosed. This large-scale patching effort is part of Microsoft’s efforts to improve the overall security posture of its software.

The majority of the patched flaws (110) are remote code execution vulnerabilities, which allow attackers to execute malicious code on a target system without requiring any further interaction. These types of vulnerabilities can have significant consequences, as they enable attackers to gain control over an affected system or extract sensitive information. Microsoft has classified 42 of these vulnerabilities as “Critical,” meaning that they pose the greatest risk to users.

The three zero-day vulnerabilities patched this month are particularly concerning, as they represent a more serious threat landscape. One of these flaws, CVE-2026-68820, was actively exploited by North Korean threat actors known as Lazarus in zero-day attacks. This vulnerability allowed attackers to gain SYSTEM privileges on affected systems, enabling them to deploy malware and conduct other malicious activities. Microsoft has credited Moshe Marelus and David Driker with Checkpoint for discovering this flaw.

The two publicly disclosed zero-days that were fixed are CVE-2026-62832, a Windows User Profile Service Elevation of Privilege Vulnerability, and CVE-2026-72971, a Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering vulnerability. While Microsoft attributed the first flaw to an anonymous researcher, details of the vulnerability match those disclosed by security researcher Nightmare Eclipse last month. This vulnerability allows attackers to gain administrator privileges on affected systems.

The increased number of patched flaws this month is largely due to Microsoft’s adoption of an AI-powered vulnerability discovery system. This system has enabled Microsoft to identify more security flaws across its software products, leading to a significant increase in Patch Tuesday updates. While the sheer scale of these patches can be overwhelming, it’s essential for users to prioritize patching their systems as soon as possible.

As we navigate this complex threat landscape, it’s crucial to remember that security is an ongoing process. Regularly updating your operating system and software products is critical to preventing exploitation by attackers. With the number of zero-days patched this month, it’s clear that Microsoft is taking steps to improve its security posture. Users should take this opportunity to review their systems’ configurations and ensure they are up-to-date with the latest patches.


Source: Bleeping Computer — 2026-08-11