Microsoft Slams Down 400 Flaws in August Patch Tuesday
Microsoft released a massive Patch Tuesday update on August 11, fixing no less than 400 vulnerabilities, including one actively exploited zero-day vulnerability.
The number of flaws is not as high as the record 570 issued in July's Patch Tuesday, but it will still pose a challenge for organizations without automated, risk-based patching programs.
The actively exploited zero-day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock. A locally authenticated attacker with low privileges could run a specially crafted application and trigger a race condition to gain system privileges and extensive control over a targeted Windows system.
Action1 co-founder Mike Walters explained that 'Confidentiality, integrity, and availability impacts are all rated high.' He added that exploitation has been detected in the wild, so deployment should be prioritized even though the vulnerability is rated important rather than critical.