August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Days
Microsoft’s August 2026 Patch Tuesday release addresses 421 vulnerabilities, including three zero-days. One zero-day was exploited in the wild, while two others were publicly disclosed before fixes were available.
Defenders must act decisively: address the active Windows elevation of privilege exploit as an immediate priority, then swiftly remediate publicly disclosed flaws and critical vulnerabilities impacting cloud workloads, core Windows infrastructure, and network-facing services.
What Did Microsoft Patch in August 2026 Patch Tuesday?
Microsoft’s August 2026 security update addresses a significant volume of security flaws, including over 60 critical vulnerabilities and three zero-days. Among these zero-day threats, one has already been reported as exploited in the wild, necessitating immediate remediation.
With this cycle, Microsoft covers a broad set of products and components, including Windows, Microsoft QUIC, Windows DNS Server, Routing and Remote Access Service, Windows SSTP, Microsoft Exchange Server, Azure services, Microsoft Teams, .NET, and Visual Studio.
What Are August 2026 Patch Tuesday Zero-Days?
The August release includes three zero-day vulnerabilities. CVE-2026-68820 should be treated as the top priority because Microsoft marked it as exploited in the wild.
| CVE | Status | Component | Impact |
|---|---|---|---|
| CVE-2026-68820 | Exploited in the wild | Windows Ancillary Function Driver for WinSock | Elevation of privilege |
| CVE-2026-62832 | Publicly disclosed | Windows User Profile Service | Elevation of privilege |
| CVE-2026-72971 | Publicly disclosed | Windows Container Isolation FS Filter Driver | Tampering |
CVE-2026-68820: Exploited Windows AFD Elevation of Privilege
CVE-2026-68820 (CVSS 7.0) affects the Windows Ancillary Function Driver for WinSock. The vulnerability can allow an attacker with local access to elevate privileges, making it especially useful after an initial compromise.
This is the first patching priority for endpoint and server fleets. Security teams should also review EDR telemetry for post-compromise behavior, privilege escalation attempts, unusual child processes, and suspicious activity around systems that were exposed before patch deployment.

Details of CVE-2026-68820 (SOCRadar Vulnerability Intelligence)
CVE-2026-62832: Publicly Disclosed Windows User Profile Service EoP
CVE-2026-62832 (CVSS 7.8) affects the Windows User Profile Service and may allow local elevation of privilege. Public disclosure increases urgency because attackers and researchers already have more context before organizations finish patching.
Prioritize endpoints, shared workstations, jump hosts, and servers where low-privilege access could become a path to administrator-level activity.

Details of CVE-2026-62832 (SOCRadar Vulnerability Intelligence)
CVE-2026-72971: Publicly Disclosed Windows Container Tampering Flaw
CVE-2026-72971 (CVSS 5.5) affects the Windows Container Isolation FS Filter Driver, also known as unionfs.sys. The issue is a local tampering vulnerability and is most relevant to systems using Windows containers or containerized workloads.
Patch container hosts, CI/CD systems, shared compute environments, and production systems where container isolation matters to workload separation.

Details of CVE-2026-72971 (SOCRadar Vulnerability Intelligence)
Which Critical Microsoft CVEs Should Teams Prioritize?
With over 60 critical vulnerabilities in the August release, security teams should focus first on exposure and business role rather than treating every CVE the same way.
- CVE-2026-62815 (CVSS 9.8) – Microsoft QUIC Remote Code Execution (RCE)
- CVE-2026-62878 (CVSS 9.8) – Windows DNS Server Remote Code Execution (RCE)
- CVE-2026-65791 (CVSS 9.8) – Windows iSCSI Target Service Remote Code Execution (RCE)
- CVE-2026-50516 (CVSS 9.4) – Azure Kubernetes Service Elevation of privilege
- CVE-2026-62817 (CVSS 8.8) – Windows DNS Server Remote Code Execution (RCE)
- CVE-2026-62820 (CVSS 8.1) – Windows DNS Server Remote Code Execution (RCE)
- CVE-2026-62889 (CVSS 8.1) – Windows SSTP Remote Code Execution (RCE)
Why Are Microsoft QUIC and DNS Server Vulnerabilities High Priority?
CVE-2026-62815 in Microsoft QUIC deserves attention because it is a critical RCE vulnerability that may be reachable over the network when affected functionality is enabled.

Details of CVE-2026-62815 (SOCRadar Vulnerability Intelligence)
The Windows DNS Server vulnerabilities also stand out. DNS servers often support domain controllers, identity infrastructure, internal name resolution, and business-critical applications. Even when exploitation requires specific conditions, DNS Server RCE flaws should be prioritized because of the role these systems play in enterprise environments.
Security teams should identify where Windows DNS Server is installed, confirm whether servers are externally reachable or restricted to internal networks, and apply the August updates to domain controllers and dedicated DNS servers early in the rollout.
What Other Microsoft Vulnerabilities Should Teams Watch?
Beyond the zero-days and the critical RCE group, teams should review vulnerabilities affecting remote access, identity, storage, cloud, and collaboration services.
High-priority areas include:
- Windows RRAS and SSTP: Prioritize systems that support remote access or VPN workflows.
- Windows iSCSI Target Service: Patch servers where the iSCSI Target role is enabled.
- Microsoft Exchange Server: Apply the August Exchange security updates and verify installation with Microsoft’s supported tooling.
- Azure and cloud services: Review Microsoft guidance for Azure Kubernetes Service, Azure Service Bus, Entra-related services, Microsoft Teams, and other cloud components in use.
- Developer and productivity tools: Include .NET, Visual Studio, GitHub Copilot and Visual Studio Code, and Office-related updates in standard deployment cycles.
Cloud service vulnerabilities may not follow the same patching model as Windows servers. Some fixes may be handled by Microsoft, while others may require customer-side validation, configuration review, or workload-specific action.
How Should Teams Prioritize August 2026 Patch Tuesday?
Security teams should use a staged process that reflects exploitation status, exposure, and business criticality.
1. Patch the Exploited Zero-Day
Deploy fixes for CVE-2026-68820 first across endpoints and servers. Treat this as a post-compromise escalation risk and review systems for signs of suspicious privilege escalation activity.
2. Patch Publicly Disclosed Zero-Days
Move quickly on CVE-2026-62832 and CVE-2026-72971. Public disclosure can shorten the time between patch release and practical abuse.
3. Address Network-Reachable Critical RCEs
Prioritize Microsoft QUIC, Windows DNS Server, RRAS, SSTP, and iSCSI Target Service based on role enablement and reachability. Internet-facing, remote-access, and tier-0 adjacent systems should move first.
4. Validate Cloud and Identity Exposure
Review Azure, Entra, Teams, and related cloud-service vulnerabilities against your tenant, subscriptions, workloads, and Microsoft guidance. Confirm whether customer action is required and document service-side remediation where Microsoft handles the fix.
5. Complete the Remaining Important Updates
Finish the rollout across Windows clients, servers, Office, .NET, Visual Studio, Exchange, and remaining Microsoft products. Verify deployment success rather than relying only on update approval.
How Can SOCRadar Help Prioritize Patch Tuesday Response?
Managing Patch Tuesday releases involving hundreds of CVEs presents a significant visibility challenge. Security teams must determine which flaws are actively exploitable, identify exposed assets, and determine which updates warrant immediate deployment outside regular maintenance schedules.
To streamline this process, SOCRadar delivers threat intelligence and exposure monitoring across two core modules:
- Cyber Threat Intelligence (CTI) Module: Tracks actively exploited and publicly disclosed vulnerabilities, severity adjustments, affected technology stacks, exploit developments, and vendor advisories. For the August 2026 Patch Tuesday, CTI keeps high-risk flaws like CVE-2026-68820, CVE-2026-62832, CVE-2026-72971, and Critical network-facing CVEs at the forefront of remediation efforts.
- Attack Surface Management (ASM) Module: Adds exposure context by discovering internet-connected assets, exposed services, vulnerable software instances, DNS records, and public infrastructure. This enables teams to focus on systems where Microsoft flaws directly overlap with external visibility, including DNS servers, remote access gateways, and publicly accessible Windows services.

SOCRadar CTI module, Vulnerability Intelligence
By combining CTI and ASM capabilities, organizations can transform an extensive CVE inventory into a prioritized remediation roadmap structured around active exploitation, external exposure, system criticality, and operational risk.
What Should Defenders Do Now?
Start by deploying the August 2026 Microsoft security updates across Windows endpoints and servers, with CVE-2026-68820 at the front of the queue. Then prioritize publicly disclosed zero-days, Critical network-facing RCEs, DNS infrastructure, remote access services, and cloud workloads that require customer-side action.
Teams should also verify deployment completion, review telemetry for privilege escalation or unusual service behavior, and rescan exposed assets after patching. The goal is to close the riskiest exposure paths first.
The full vendor list is available through Microsoft’s Security Update Guide release notes for August 2026.

