Microsoft Patch Tuesday Addresses 421 Vulnerabilities Across Various Products
Microsoft has released its August 2026 security update, which addresses 421 vulnerabilities across various products. Among them, 62 are marked as 'critical.' The update includes a vulnerability, CVE-2026-68820, that has been exploited in the wild. It's an elevation of privilege flaw affecting Windows Ancillary Function Driver for WinSock, with a CVSS base score of 7.0.
Microsoft considers exploitation more likely for several vulnerabilities. One is CVE-2026-62893, a remote code execution vulnerability affecting Windows Deployment Services TFTP Server. It has a CVSS base score of 9.8 and could allow an unauthorized attacker to execute code over a network.
The update also addresses elevation of privilege vulnerabilities in Azure SRE Agent and Microsoft Azure Kubernetes Service. Additionally, several remote code execution vulnerabilities affect Microsoft Office, including those affecting Excel and Word.