Microsoft August Patch: 421 CVEs Fixed, Zero-Day Exploited
Microsoft’s August Patch Tuesday fixes 421 CVEs, including a use-after-free zero-day in afd.sys (CVE-2026-68820) exploited to gain SYSTEM privileges.
Microsoft released its August Patch Tuesday updates on Tuesday, addressing 421 tracked vulnerabilities across Windows and related products. The release includes a use-after-free zero-day in the Ancillary Function Driver for WinSock (afd.sys), tracked as CVE-2026-68820, that has been exploited in the wild to elevate privileges to SYSTEM.
Microsoft wrote that “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required.” The company did not provide further details about the observed attacks.
Tenable senior staff research engineer Satnam Narang noted the afd.sys flaw follows a pattern of high-value exploits against that driver and pointed to three other afd.sys zero-days exploited since 2022. He added: “CVE-2024-38193 was reportedly exploited by North Korean hackers linked to the Lazarus group.”
Microsoft also highlighted CVE-2026-62832, an improper link resolution before file access vulnerability in the User Profile Service, which it described as publicly disclosed and likely to be exploited. Microsoft explained that an authenticated attacker with credentials for another local account could run a crafted application to load another user’s registry hive, potentially accessing or modifying that user’s data and gaining administrator privileges without user interaction. CVE-2026-72971 in the Windows Container Isolation FS Filter Driver (unionfs.sys) was also marked publicly disclosed but assessed as unlikely to be exploited.
Security researchers called attention to several remote code execution flaws and an elevation-of-privilege issue. These include RCEs in Windows DNS Server (CVE-2026-62878), Windows Deployment Services TFTP server (CVE-2026-62893), Microsoft QUIC (CVE-2026-62815) and Microsoft HPC Pack (CVE-2026-59124), plus an EoP in Exchange Server (CVE-2026-62911), according to external researchers.
The August updates resolve 236 Windows vulnerabilities, 98 in Office, 98 in Office 2016, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, seven in Exchange Server, one in Defender and six in other products. The package also fixes two non-Microsoft issues in the TPM 2.0 reference implementation: a spoofing bug (CVE-2026-6726) and an information disclosure flaw (CVE-2026-6727).
Microsoft’s advisories include technical summaries and mitigation guidance for each vulnerability. Several of the patched bugs affect kernel and profile-management code paths that can be used to raise privileges on compromised hosts.








