Microsoft patches 421 CVEs in August 2026
Microsoft’s August 2026 Patch Tuesday fixes 398 to 421 vulnerabilities, including at least one actively exploited zero-day.
Microsoft released its August 2026 security updates, and several cybersecurity firms reported different totals for the patch set, ranging from 398 to 421 fixed vulnerabilities. The common thread across the analyses is that the cycle includes several zero-days, including at least one actively exploited one.
Microsoft released its August 2026 Patch Tuesday, and security firms published different counts for the scope of the package, which ranges from 398 to 421 fixed vulnerabilities. Across the analyses, the consensus is that the cycle includes several zero-days, including at least one actively exploited one.
What did Microsoft fix?
Microsoft fixed between 398 and 421 vulnerabilities in its August 2026 Patch Tuesday, according to different security firms, and the package includes several zero-days, including at least one actively exploited one.
ISC SANS said the August 2026 cycle includes patches for 418 vulnerabilities, with 62 critical issues, one exploited in the wild, and two publicly disclosed as zero-days. BleepingComputer, meanwhile, said Microsoft fixed 400 flaws and that three of them were zero-days, one of them actively exploited. The Hacker News reported a total of 398 flaws and said a Windows driver had a zero-day under active attack.
SecurityWeek put the total at 421 CVEs and broke them down by product: 236 vulnerabilities in Windows, 98 in Office, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, 7 in Exchange Server, 1 in Defender, and 6 in other products. Qualys also placed the total at 421 vulnerabilities, with 62 critical and 357 important, and said Microsoft fixed three zero-days in total, two publicly disclosed and one exploited in the wild.
Tenable and Ivanti agreed on another count, 398 CVEs, with 42 critical, 355 important, and one moderate. Both firms said there were three zero-days, one exploited in the wild and two publicly disclosed. Cisco Talos, for its part, said Microsoft covered 421 vulnerabilities and that one of the flaws disclosed this month was exploited in the wild.
Which zero-day was under attack?
CVE-2026-68820 was identified by Rapid7 as an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock, with exploitation detected.
Rapid7 identified CVE-2026-68820 as an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock, with exploitation detected. Tenable also mentioned that CVE in its monthly analysis, while The Hacker News pointed to a Windows driver as the component affected by the zero-day under active attack.
What did the August patch picture look like?
Fortra said that, at the time of its analysis, there were no new advisories included with Microsoft Security Guidance for August.
Beyond the differences in the final number reported by each source, the consensus across the analyses is that this was one of Microsoft’s largest monthly updates of 2026, with multiple critical flaws and at least one confirmed case of active exploitation.
Sources
- Microsoft Patch Tuesday August 2026isc.sans.edu· ISC SANS
- Patch Tuesday - August 2026rapid7.com· Rapid7
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysbleepingcomputer.com· BleepingComputer
- August 2026 Microsoft Patch Tuesdaytenable.com· Tenable
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attackthehackernews.com· The Hacker News
- Microsoft Patch Tuesday for August 2026 — Snort rulesblog.talosintelligence.com· Cisco Talos Intelligence
- 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked onetheregister.com· The Register
- August 2026 Patch Tuesdayivanti.com· Ivanti
- Microsoft Fixes 421 CVEs, One Exploited Zero-Daysecurityweek.com· SecurityWeek
- August 2026 Patch Tuesday Analysisfortra.com· FortraUnverified URL
- Microsoft Patch Tuesday, August 2026 Security Update Reviewblog.qualys.com· Qualys



