Microsoft's August Patch Tuesday release fixes 421 vulnerabilities, including a Windows zero-day that attackers have already exploited in the wild. The exploited flaw, tracked as CVE-2026-68820, is a use-after-free bug in afd.sys, the kernel-mode driver underpinning the Windows Sockets API, and it can hand attackers SYSTEM privileges on a Windows PC.
The count itself is contested. Microsoft's figure of 421 is what the company reports, but some security researchers put the number at 398 newly addressed vulnerabilities.
Critical totals vary too, with published counts ranging from 42 to 62, and one account from the IT Security News write-up describes the exploited afd.sys flaw as having been used to gain SYSTEM privileges.
Windows dominates the release, accounting for 236 of the listed issues, with Office following at 98 vulnerabilities. The fixes span Windows, Office, Exchange Server, SharePoint, and Azure.
Windows 11 versions 24H2 and 25H2 receive the patches through KB5121003, advancing to builds 26100.9168 and 26200.9168, while Windows 11 26H1 gets KB5121000 and moves to build 28000.2704. Eligible Windows 10 systems enrolled in Extended Security Updates continue to receive fixes, with KB5120249 applying to Windows 10 21H2 ESU installations.
Home users can grab the cumulative updates through Windows Update.
Beyond the exploited flaw, Microsoft addressed two publicly disclosed zero-days. CVE-2026-62832 is an elevation-of-privilege bug in the Windows User Profile Service that lets an authenticated attacker load another user's registry hive and gain administrator privileges, and it was publicly disclosed before a patch existed.
A third zero-day, CVE-2026-72971, is a tampering vulnerability in the Windows Container Isolation FS Filter Driver. Microsoft has not confirmed exploitation of the two publicly disclosed flaws.
The release also includes several critical remote code execution flaws that require no user interaction. A Windows DNS Server vulnerability that could be wormable allows remote, unauthenticated attackers to execute code with elevated privileges, and researchers flagged it because it can be reached without authentication or user interaction.
A separate flaw in Microsoft's QUIC implementation affects roughly 13.5 million websites, with successful exploitation requiring an attacker to win a race condition.
Security researchers have been scrutinizing the patch set closely. One outlet reported that a researcher known as Nightmare Eclipse published details and proof-of-concept code for a new Windows zero-day dubbed "ShieldBreak" just hours after Microsoft shipped fixes, and that the same researcher has released 10 zero-days targeting Microsoft since April amid a dispute over vulnerability handling.
The August update also tweaks File Explorer, Windows Hello, touchpad scrolling and zoom controls, Windows Search, and several Start menu and Taskbar behaviors.













