Decoding the world of cybersecurity

Microsoft August patch load tops 400 flaws

Microsoft’s August security release covers 421 vulnerabilities, including an exploited Windows privilege-escalation flaw, as enterprise patch volumes remain far above historic norms.

Microsoft August patch load tops 400 flaws
Summary
  • Rapid7 counted 421 vulnerabilities in Microsoft’s August Patch Tuesday release, including 236 affecting Windows.
  • One newly published Windows vulnerability, CVE-2026-68820, was already being exploited in the wild.
  • The month also includes the second half of a critical SharePoint exploit chain and several high-severity server vulnerabilities.

Microsoft’s August security release contains more than 400 vulnerabilities, keeping enterprise patch volumes near historically high levels while combining one actively exploited Windows flaw with serious weaknesses across server and collaboration infrastructure.

Rapid7 counted 421 vulnerabilities in the August release from Microsoft, including 236 affecting Windows. Counting methodologies can differ between security companies depending on which products and advisory types they include, but the overall scale places August among the largest Patch Tuesday releases on record.

The most urgent issue is CVE-2026-68820, an elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock. Microsoft has marked exploitation as detected. Successful exploitation can provide SYSTEM-level privileges, although the race-condition nature of the flaw raises the technical difficulty of producing reliable exploitation.

CVE-2026-68820 has already been tied to attacks attributed by Check Point to the Lazarus Group against defence-related targets, including organisations in France and Germany. The European defence campaign gives the exploited flaw its own incident context, while the wider August release creates a separate remediation problem across Microsoft estates.

The release also contains the second component of a critical SharePoint exploit chain discovered by Rapid7. CVE-2026-63520 is a high-severity remote-code-execution vulnerability that can be combined with CVE-2026-55040, a SharePoint authentication bypass patched in July, to produce an unauthenticated RCE path against vulnerable servers.

Microsoft’s July release had already included exploited SharePoint and AD FS vulnerabilities, while a different SharePoint flaw has since been linked to ransomware activity. The succession of issues puts on-premises Microsoft infrastructure under particular patching pressure.

Other August Windows vulnerabilities include high-severity remote-code-execution flaws in Active Directory Certificate Services, Active Directory Domain Services, Windows Deployment Services, and additional operating-system components. Not every high-scoring vulnerability is equally likely to be exploited, and Microsoft’s exploitability assessments vary across the release.

The size of the monthly update has become an operational problem in its own right. Large enterprises cannot assess hundreds of vulnerabilities solely by CVSS score. Exposure, asset role, authentication requirements, internet reachability, existing exploitation, available mitigations, business criticality, and the consequences of patching all influence remediation order.

That creates a widening gap between patch publication and patch completion. Endpoint updates can often be deployed through established management systems, but domain controllers, certificate services, collaboration servers, application hosts, and other infrastructure may require compatibility testing or scheduled maintenance windows.

The problem becomes more pronounced where organisations still operate older on-premises platforms alongside Microsoft cloud services. Cloud-hosted infrastructure may receive security changes through the provider, while locally managed servers remain dependent on internal asset inventories, ownership, testing, and change control.

Rapid7’s count also illustrates how the vulnerability-management baseline has shifted during 2026. August is below July’s record volume but remains substantially larger than monthly releases that would previously have been considered exceptional.

That volume makes prioritisation increasingly dependent on threat intelligence and architecture rather than patch totals. A single exploited privilege-escalation flaw may demand faster action than dozens of theoretically critical defects that are unreachable in a particular environment, while an unpatched identity or collaboration server can carry disproportionate consequences because of the data and privileges around it.

August therefore presents two simultaneous problems: several individually serious vulnerabilities and a continuing increase in the amount of remediation work expected from organisations running broad Microsoft estates. The first can be solved vulnerability by vulnerability; the second is becoming a question of whether patching processes, asset ownership, and maintenance capacity can keep pace with the software they support.

×