CiberLATAMbywhalemate

Microsoft patches 421 CVEs in August 2026

Microsoft’s August 2026 Patch Tuesday fixes 398 to 421 vulnerabilities, including at least one actively exploited zero-day.

Whalemate Labs · AI-assisted researchPublished:3 min read

Microsoft released its August 2026 security updates, and several cybersecurity firms reported different totals for the patch set, ranging from 398 to 421 fixed vulnerabilities. The common thread across the analyses is that the cycle includes several zero-days, including at least one actively exploited one.

Microsoft released its August 2026 Patch Tuesday, and security firms reported different counts for the scope of the update set, ranging from 398 to 421 patched vulnerabilities. What all of the analyses agree on is that the cycle includes multiple zero-days, including at least one that was actively exploited.

What Microsoft fixed

ISC SANS reported that the August 2026 cycle includes patches for 418 vulnerabilities, with 62 rated critical, one exploited in the wild, and two publicly disclosed zero-days. BleepingComputer, meanwhile, said Microsoft fixed 400 flaws and that three of them were zero-days, one of which was actively exploited. The Hacker News reported a total of 398 flaws and said a Windows driver had a zero-day under active attack.

SecurityWeek put the total at 421 CVEs and broke the fixes down by product: 236 vulnerabilities in Windows, 98 in Office, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, 7 in Exchange Server, 1 in Defender, and 6 in other products. Qualys also placed the total at 421 vulnerabilities, with 62 critical and 357 important-severity issues, and said Microsoft fixed three zero-days in all, two publicly disclosed and one exploited in the wild.

Tenable and Ivanti used another count, 398 CVEs, with 42 critical, 355 important, and one moderate issue. Both firms said there were three zero-days, one exploited in the wild and two publicly disclosed. Cisco Talos, for its part, said Microsoft addressed 421 vulnerabilities and that one of the flaws disclosed this month had been exploited in the wild.

The zero-day under attack

Rapid7 identified CVE-2026-68820 as an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock, with exploitation detected. Tenable also mentioned that CVE in its monthly analysis, while The Hacker News pointed to a Windows driver as the component affected by the zero-day under active attack.

August patch roundup

Fortra said that, at the time it published its analysis, there were no new advisories included with Microsoft Security Guidance for August. Beyond the differences in the final counts reported by each source, the consensus across the analyses is that this was one of Microsoft’s largest monthly updates of 2026, with multiple critical flaws and at least one confirmed case of active exploitation.

Sources

View all