Microsoft Fixes Critical Vulnerabilities in August Update
Microsoft has released its August update to address security vulnerabilities across Windows, Office, Exchange Server, and cloud services. The update patches 398 new vulnerabilities, with 42 classified as critical. A significant number of these flaws can be exploited remotely without user interaction.
The most notable issue is a Windows Winsock flaw (CVE-2026-68820) that has already been attacked in the wild. Attackers can gain elevated privileges by combining this exploit with another remote code execution vulnerability.
Other critical vulnerabilities include RCE flaws in the DNS server, TFTP server, and QUIC protocol. Microsoft advises users to install these updates immediately to protect their systems from potential exploitation.