Microsoft's August Patch Tuesday Brings Record-Breaking 751 Fixes
Microsoft's August Patch Tuesday saw a massive update of 751 fixes across all product families, with 108 rated as critical. This month's release includes one exploited Windows flaw, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). The Readiness team has provided an infographic on deployment risks for this Microsoft August update.
The security-only release earned Patch Now for Windows, Office, and Exchange; no SQL Server updates were made this month. However, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw.
The August Windows Server 2025 (KB5120233) and 2022 (KB5120242) updates still list WSUS synchronization error details, with the detail pane removed to address a remote code execution flaw CVE-2025-59287. The Readiness team recommends that all recovery keys are retrievable before restarting freshly patched servers.