Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack
Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs. The post Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack appeared first on TechRepublic .
Microsoft's August Patch Tuesday witnessed the release of over 400 security patches, including a critical zero-day vulnerability already under active exploitation. This patch update tackled a range of issues, from local privilege escalation flaws to critical remote code execution (RCE) bugs. Among these, CVE-2026-68820 stood out as the most pressing threat, allowing low-privileged attackers to gain SYSTEM-level access through a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys).
North Korean hackers were reportedly leveraging this vulnerability in Operation Dream Job, marking the fourth such exploit since 2022.
Other critical vulnerabilities included CVE-2026-62832, a Windows User Profile Service elevation-of-privilege flaw, and four zero-day vulnerabilities, each with a CVSS score of 9.8, requiring no authentication or user interaction. Microsoft's CEO and Co-Founder, Alex Vovk, warned that these vulnerabilities posed significant risks due to their ease of exploitation.
The rollout of these updates presented a significant challenge for IT departments, as the sheer volume of patches made blanket deployments risky. Organizations had to balance the need for immediate patching to mitigate known threats with the risk of operational disruption. Furthermore, the emergence of new zero-day exploits, such as Nightmare Eclipse's "ShieldBreak," added another layer of complexity.
This vulnerability bypassed Microsoft's July patch for CVE-2026-50656, allowing attackers to elevate local permissions to SYSTEM privileges on Windows 10, Windows 11, and Windows Server 2025.
Security experts urged organizations to deploy patches cautiously, prioritizing the most critical vulnerabilities while implementing additional security measures, such as limiting local user privileges and employing alternative threat-hunting queries. The ongoing debate over how Microsoft handles vulnerability reports and previous legal threats from threat actors added a political dimension to the patch management discussion.
Written by urgent.news from TechRepublic's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.