Security

Microsoft August Patch Tuesday Fixes 398 CVEs, Including Three Zero-Days and a Wormable DNS Flaw

Microsoft's August 11 update addressed 398 CVEs — three of them zero-days, one actively exploited — plus a wormable DNS flaw enabling remote code execution, across Windows, Exchange, SharePoint, GitHub Copilot and more.

R
By Ravi Menon Security Correspondent
August 12, 2026 / Updated August 19, 2026 / 5 min read

Microsoft's August Patch Tuesday release, published August 11, fixed 398 vulnerabilities — including three zero-days, one confirmed exploited in the wild — plus a wormable DNS flaw enabling remote code execution, according to Tenable and SecurityAffairs.

The Critical Fixes

The exploited flaw is CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock (AFD.sys) that attackers — including the North Korea-linked Lazarus Group — have used to escalate privileges and deploy backdoors. The release also covers a wormable DNS remote-code-execution bug and fixes spanning Windows HTTP.sys, Hyper-V, NTFS, Desktop Window Manager, Exchange Server, SharePoint, Teams, Dynamics Business Central, GitHub Copilot, Visual Studio Code, .NET and Azure services.

Patch Pressure

The August release lands as CISA adds actively exploited flaws to its Known Exploited Vulnerabilities catalog — including the Cisco Secure Firewall ASA/FTD heap-inspection bug CVE-2026-20349 and a Metabase SQL injection rated CVSS 10.0 that exposed connected database credentials at five companies. Security teams are being urged to prioritize the three zero-days and the DNS bug, which can spread without user interaction.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.