Microsoft
Microsoft addresses 400 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.
Patch Tuesday addressed 42 "Critical" vulnerabilities, 37 of which are remote code execution and 5 are elevation of privilege. 357 rated as important and one rated as moderate.
Zero-day vulnerabilities
This month’s Patch Tuesday addresses three zero-day vulnerabilities, one actively exploited and two publicly disclosed.
CVE-2026-68820 - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability carries a CVSS v3 score of 7.0 and is classified as an Important. The vulnerability can be exploited by a local attacker to obtain SYSTEM-level privileges. Microsoft has confirmed that the flaw was already being exploited in the wild as a zero-day before the security update was released.
The other two vulnerabilities, CVE-2026-61348 and CVE-2026-70307, were also assigned CVSS v3 scores of 7.0. There are currently no reports of active exploitation involving either flaw. Nevertheless, Microsoft has rated both vulnerabilities as “Exploitation More Likely” under its Exploitability Index, indicating that attackers may be more likely to develop working exploits for them in the future.
CVE-2026-62832 is an elevation-of-privilege vulnerability in the Windows User Profile Service. The flaw carries a CVSS v3 score of 7.8 and has been classified as Important. If successfully exploited, a local attacker could escalate their privileges to Administrator level. The vulnerability was publicly disclosed before a fix was released and is rated “Exploitation More Likely” under Microsoft’s Exploitability Index.
CVE-2026-72971 is a tampering vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys). Rated Important, the flaw has a CVSS v3 score of 5.5 and was publicly disclosed before Microsoft released a security fix. A successful attack could enable a local threat actor to modify or tamper with data. Despite the prior disclosure, Microsoft considers exploitation of the vulnerability “Exploitation Unlikely.”
Critical
CVE-2026-62823 is a critical remote code execution vulnerability in the Windows DHCP Server. The flaw carries a CVSS v3 score of 8.8 and is rated “Exploitation More Likely”. An unauthenticated attacker with network access could exploit a heap-based buffer overflow using a specially crafted packet, potentially allowing arbitrary code execution from an adjacent network.
Microsoft also addressed 13 additional vulnerabilities in the Windows DHCP Server this month. While these flaws could pose security risks, they were all classified as Important rather than Critical.
CVE-2026-62893 is a critical remote code execution vulnerability affecting the Windows Deployment Services Trivial File Transfer Protocol (TFTP) Server. The flaw has a CVSS v3 score of 9.8 and is rated “Exploitation More Likely” under Microsoft’s Exploitability Index. An unauthenticated remote attacker could exploit vulnerability by sending specially crafted packets to the affected service, potentially leading to arbitrary code execution.
CVE-2026-65665, CVE-2026-63520 and CVE-2026-70355 affecting Microsoft Office SharePoint were rated as critical and were assessed as 'Exploitation More Likely.' The month’s security updates also address 27 additional SharePoint vulnerabilities, all of which are rated Important and considered “Exploitation Less Likely.”
Important
CVE-2026-58650 A security feature bypass vulnerability affecting Visual Studio Code. The vulnerability is rated Important and Microsoft has assessed it as “Exploitation More Likely” under its Exploitability Index. Successful exploitation could allow an attacker to bypass a security feature on an affected system, potentially weakening existing security protections. Microsoft addressed the vulnerability as part of its August 2026 Patch Tuesday security updates.
CVE-2026-59124 A remote code execution vulnerability affecting Microsoft High-Performance Computing (HPC) Pack. It is rated Important, with Microsoft classifying the flaw as “Exploitation More Likely.” Successful exploitation could allow an attacker to execute arbitrary code on an affected HPC Pack installation, making the vulnerability particularly relevant to organisations using Microsoft's high-performance computing infrastructure.
CVE-2026-61930 An elevation-of-privilege vulnerability affecting the Windows Kernel. The flaw is rated Important and has been assessed by Microsoft as “Exploitation More Likely.” Successful exploitation could allow an attacker to elevate their privileges on an affected Windows system, potentially gaining access to resources and capabilities normally restricted to higher-privileged users
Recent updates from other Vendors
Adobe released security updates for vulnerabilities in Coldfusion, Commerce, Lightroom Classic, Content Credentials SDK, and Campaign Classic.
Cisco has issued security updates addressing vulnerabilities across several products, including Cisco Catalyst SD-WAN, IOS, IOS XE, and ClamAV, with some of the flaws already subject to public exploitation.
SAP in its August security updates covered vulnerabilities across multiple products, including CVE-2026-58231 a critical improper authorization flaw in SAP Commerce Cloud (Data Hub Adapter) rated CVSS 10.0.
VMware released security updates for VMware Avi Load Balancer, which include authentication bypasses and remote code execution flaws.
Fortinet has released its August 2026 security updates, addressing vulnerabilities across its product portfolio, including FortiManager. Among the issues fixed is CVE-2026-70468, an authentication bypass vulnerability in FortiManager that could allow a remote, unauthenticated attacker to bypass authentication through an alternative path or channel.
Ivanti has released its August 2026 security updates, addressing vulnerabilities in Ivanti Neurons for MDM and Ivanti Endpoint Manager (EPM).
Check Point released security updates addressing multiple vulnerabilities. Customers are advised to apply the latest hotfixes and patches.
Palo Alto Networks released updates across its security product portfolio. Recent releases include updates for PAN-OS, Next-Generation Firewall, GlobalProtect, Prisma Access, Advanced WildFire, Panorama, Enterprise DLP, Advanced DNS Security, Advanced IP Defense, and Strata Cloud Manager. The company’s release notes show multiple updates throughout August, including PAN-OS 11.1 and 11.2 releases and updates to its cloud-delivered security services.
As always, users are strongly advised to install the latest security updates as soon as they become available to ensure your systems remain protected against known vulnerabilities and potential cyber threats. Applying updates promptly helps reduce the risk of exploitation, improves overall system stability, and ensures continued protection against emerging security risks.
