Software

Microsoft's August Patch Tuesday Fixes 421 CVEs Including a WinSock Zero-Day Under Active Attack

Microsoft shipped 421 security fixes on August 11, 2026, including a WinSock zero-day tracked as CVE-2026-68820 that is being exploited in the wild, plus 62 critical-rated flaws across Windows, Exchange Server, Office, and SharePoint.

M
By Marcus Lin Enterprise Software Reporter
August 15, 2026 / Updated August 19, 2026 / 7 min read

Microsoft's August 2026 Patch Tuesday, released on August 11, addresses 421 common vulnerabilities and exposures across Windows, Microsoft Office, SharePoint Server, Azure services, .NET, PowerShell, Visual Studio Code and the rest of its enterprise portfolio, Cybersecurity News and Qualys reported. Of those, 62 are rated critical and three are zero-days being actively exploited in the wild — making this one of the heaviest Patch Tuesdays of the year for security teams.

The WinSock Zero-Day

The most urgent item is CVE-2026-68820, a WinSock privilege-escalation vulnerability that Microsoft says is under active exploitation. Successful exploitation gives an attacker system-level privileges on affected Windows 11 26H1 and Windows 10 22H2 machines, operating as a critical step in ransomware and hands-on intrusion chains. Administrators are being urged to prioritize the relevant cumulative update — KB5121000 for Windows 11 26H1 and KB5120249 for Windows 10 22H2 — within the next 48 hours.

Exchange and SharePoint in the Spotlight

Exchange Server and SharePoint Server together account for more than 90 of this month's critical fixes, including remote code execution flaws in on-premises Exchange that several security vendors flagged as "wormable" within an Exchange organization. Petri.com counted 398 vulnerabilities in its tally and Tech-Insider counted 440 CVEs when including MITRE-assigned IDs, reflecting different counting conventions; Microsoft-assigned CVEs alone land at 400. The wide variance underscores the need for administrators to rely on the official Microsoft Security Update Guide rather than summary counts.

What Security Teams Should Do

Beyond the WinSock zero-day, defenders should prioritize Exchange Server cumulative updates, SharePoint Server patches for two CVSS 9.8-rated deserialization flaws, and the Office remote-code-execution cluster tied to legacy Equation Editor components. "The volume alone — 421 CVEs including 62 critical — means patches can't be applied in a single maintenance window; teams need to triage, sequence, and verify," the Qualys research team wrote. With the WinSock vulnerability already weaponized, expect active scanning within days of disclosure.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.