Microsoft Addresses 398 Vulnerabilities in August 2026 Patch Tuesday Updates
Microsoft released its August 2026 Patch Tuesday updates, addressing 398 vulnerabilities across various products. This includes 62 critical vulnerabilities that have been patched in Windows, Exchange Server, Azure AD, and Entra services.
The company also reminded customers that Windows 11 version 24H2 Home and Pro editions will reach end of support on October 13, 2026, after which they will no longer receive security updates or technical support.
Among the most critical vulnerabilities patched this month are elevation-of-privilege bugs in Windows Ancillary Function Driver for WinSock and Windows User Profile Service. A remote code execution vulnerability in Windows DNS Server was also addressed, as well as a critical flaw in Windows Deployment Services TFTP Server that could be exploited without user interaction.
Microsoft recommends that organizations conduct thorough testing before deploying the patches widely on production systems, as hackers may start to work out how to weaponize newly reported vulnerabilities. The company advises users to back up their systems before applying updates and use built-in backup tools in case of issues.