Microsoft's Patch Tuesday Update Tackles 421 Vulnerabilities
Microsoft's Patch Tuesday update for August released fixes for 421 unique Common Vulnerabilities and Exposures (CVEs), including two zero-day vulnerabilities. The update addresses critical issues in various Microsoft products, with 236 affecting Windows, 98 affecting Office and Office 2016 each, and 30 affecting SharePoint Server.
The CVEs are rated as Critical, Important, or Moderate severity bugs, with 44 assessed as Critical. A significant number of vulnerabilities, 180, allow elevation of privilege (EoP) issues that grant attackers full SYSTEM level privileges on affected devices.
Tyler Reguly, associate director of security R&D at Fortra, noted, 'Yes, there are 421 Microsoft CVEs. Yes, that is a lot to deal with.' He emphasized the importance of prioritizing vulnerabilities based on their severity and potential impact.
The highest priority bugs include CVE-2026-68820 (CVSS: 7.0) in Windows Ancillary Function Driver for WinSock, which allows attackers to elevate privileges without user interaction; and CVE-2026-62832 (CVSS: 7.8), a publicly known vulnerability that Microsoft believes will be exploited soon.