Microsoft Patch Tuesday Brings Record-Breaking Fixes for 421 Vulnerabilities
Microsoft released its August 2026 Patch Tuesday on August 11, fixing 421 CVEs in a single release. This is one of the largest patch releases in recent history, with 62 Critical-rated vulnerabilities and three zero-days confirmed by Microsoft.
The actively exploited zero-day, CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock (afd.sys) and allows local attackers to escalate their privileges to SYSTEM. This vulnerability is considered a high-priority fix due to its potential impact on security.
Other critical vulnerabilities include remote code execution flaws in Windows DNS Server, Microsoft QUIC, TFTP server, and HPC Pack. These bugs can be triggered without authentication or user interaction, making them particularly concerning for organizations with exposed servers.