Microsoft's August 2026 Patch Tuesday, released on August 11, addresses 421 common vulnerabilities and exposures across Windows, Microsoft Office, SharePoint Server, Azure services, .NET, PowerShell, Visual Studio Code and the rest of its enterprise portfolio, Cybersecurity News and Qualys reported. Of those, 62 are rated critical and three are zero-days being actively exploited in the wild — making this one of the heaviest Patch Tuesdays of the year for security teams.
The WinSock Zero-Day
The most urgent item is CVE-2026-68820, a WinSock privilege-escalation vulnerability that Microsoft says is under active exploitation. Successful exploitation gives an attacker system-level privileges on affected Windows 11 26H1 and Windows 10 22H2 machines, operating as a critical step in ransomware and hands-on intrusion chains. Administrators are being urged to prioritize the relevant cumulative update — KB5121000 for Windows 11 26H1 and KB5120249 for Windows 10 22H2 — within the next 48 hours.
Exchange and SharePoint in the Spotlight
Exchange Server and SharePoint Server together account for more than 90 of this month's critical fixes, including remote code execution flaws in on-premises Exchange that several security vendors flagged as "wormable" within an Exchange organization. Petri.com counted 398 vulnerabilities in its tally and Tech-Insider counted 440 CVEs when including MITRE-assigned IDs, reflecting different counting conventions; Microsoft-assigned CVEs alone land at 400. The wide variance underscores the need for administrators to rely on the official Microsoft Security Update Guide rather than summary counts.
What Security Teams Should Do
Beyond the WinSock zero-day, defenders should prioritize Exchange Server cumulative updates, SharePoint Server patches for two CVSS 9.8-rated deserialization flaws, and the Office remote-code-execution cluster tied to legacy Equation Editor components. "The volume alone — 421 CVEs including 62 critical — means patches can't be applied in a single maintenance window; teams need to triage, sequence, and verify," the Qualys research team wrote. With the WinSock vulnerability already weaponized, expect active scanning within days of disclosure.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.