Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack

Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack

Microsoft patches over 400 flaws as rogue zero-day lands. Image: CROCOTHERY/Adobe Stock

Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.

Aug 13, 2026

Microsoft released patches for over 400 CVEs this Patch Tuesday, including one actively exploited zero-day and several critical remote code execution flaws that require no user interaction.

Security teams face the challenge of triaging this overwhelming volume while managing the risk of patching itself.

The zero-day that matters most

CVE-2026-68820 is the vulnerability demanding immediate attention. This use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) allows a locally authenticated attacker with low privileges to gain SYSTEM-level access.

“The primary threat is local privilege escalation,” Mike Walters, President and Co-Founder of Action1, told TechRepublic. “An attacker who already has low-privileged access could exploit the vulnerability to gain SYSTEM privileges, potentially obtaining extensive control over the affected Windows system.”

Check Point Research reported that North Korean attackers have been using the vulnerability in a new wave of the Operation Dream Job campaign to deploy kernel-mode rootkits.

This marks the fourth afd.sys zero-day exploited in the wild since 2022, with previous iterations linked to Lazarus Group activity.

A second vulnerability, CVE-2026-62832, was publicly disclosed before a patch was available.

This Windows User Profile Service elevation-of-privilege flaw allows an authenticated attacker to load another user’s registry hive and gain administrator privileges. While not yet exploited in the wild, Microsoft assesses exploitation as “More Likely,” making it a high priority for deployment.

The four 9.8s: No click, no credentials required

Four critical vulnerabilities carry CVSS scores of 9.8 and require no authentication or user interaction:

  • CVE-2026-62878 (Windows DNS Server): A stack-based buffer overflow that the Zero Day Initiative describes as technically wormable
  • CVE-2026-62893 (Windows Deployment Services TFTP server)
  • CVE-2026-62815 (Microsoft QUIC)
  • CVE-2026-59124 (Microsoft HPC Pack) — rated Important rather than Critical since HPC Pack isn’t installed by default
Advertisement

“An unauthenticated attacker can send a specially crafted packet to an affected service over the network and potentially execute code on the target system,” said Alex Vovk, CEO and Co-Founder of Action1, describing the DNS Server flaw.

A SharePoint chain completed

August closes the second half of a two-part SharePoint fix that began in July. Rapid7 Labs reported an exploit chain combining an authentication bypass (CVE-2026-55040, patched in July) with a code execution vulnerability (CVE-2026-63520, patched this month) to achieve unauthenticated remote code execution against on-premises SharePoint servers.

If you applied July’s update, that attack route is already blocked. The August fix now closes the RCE component as well.

The ‘ShieldBreak’ exploit drop

Just hours after Microsoft published its fixes, security researcher “Nightmare Eclipse” published details and proof-of-concept code for a brand-new Windows zero-day dubbed “ShieldBreak.”

The flaw bypasses Microsoft’s July patch for CVE-2026-50656 (RoguePlanet) and targets Windows Defender, allowing an attacker to elevate local permissions to SYSTEM privileges on Windows 10, Windows 11, and Windows Server 2025.

Security expert Kevin Beaumont confirmed the exploit works on fully patched systems.

Nightmare Eclipse has now released 10 zero-days targeting Microsoft since April, driven by an ongoing dispute over the tech giant’s handling of vulnerability reports and previous threats of legal action.

A Microsoft spokesperson told TechCrunch the company is “aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims.”

Strategic defender prioritization

The sheer volume of monthly security updates presents a structural challenge for enterprise IT departments, making blanket deployments nearly impossible without risking operational disruption.

Amol Sarwate, Head of Security Research and REDLab at Cohesity, emphasized the operational risk of combining flaws.

“Used together, the two vulnerabilities could turn an initial foothold — such as a successful phishing attack — into a complete system compromise. That makes this pair the clear priority for defenders this month,” Sarwate told TechRepublic.

Advertisement

The simultaneous arrival of hundreds of official fixes alongside unpatched, publicly disclosed zero-days leaves system administrators facing an impossible balancing act. Rushing patch deployments without testing risks crashing critical production environments, yet delaying leaves endpoints exposed to active exploits like CVE-2026-68820.

Furthermore, because ShieldBreak targets Windows Defender directly, standard endpoint protection tools may fail to stop local privilege escalation until Microsoft releases an official fix.

Organizations must rely on alternative threat-hunting queries and strictly limit local user privileges to slow down potential attackers already inside the network.

Also read: Our Windows 11 security cheat sheet explains how Microsoft Defender, BitLocker, passkeys, and other built-in protections work together.

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.