Protect.Computer
NEWS

Microsoft Patches 400 Flaws Including Actively Exploited Zero-Day

· 1 min read · Device safety Malicious byte
Microsoft Patches 400 Flaws Including Actively Exploited Zero-Day

Microsoft’s August 2026 Patch Tuesday delivers fixes for 400 security vulnerabilities across Windows, Office, Azure, and other products — one of the largest single-month releases in recent memory. Three of those flaws are zero-days: one actively exploited in attacks and two publicly disclosed without a patch before today.

The actively exploited zero-day is CVE-2026-68820, a privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock. Attackers who already have a foothold on a Windows machine can exploit this flaw to elevate their privileges to SYSTEM level, the highest permission tier on the operating system. Microsoft has not disclosed who is exploiting the flaw or how widely it is being used. Of the 400 vulnerabilities fixed this month, 42 are rated Critical — 37 of those are remote code execution flaws that could let an attacker run malicious code without user interaction. The remaining vulnerability categories include 176 privilege escalation bugs, 110 remote code execution issues, 86 information disclosure flaws, and 21 spoofing vulnerabilities. Microsoft noted that it recently deployed an AI-powered vulnerability discovery system, which it credits with the sharp increase in flaws identified and patched each month compared to prior years.

How to check if you’re affected

Affected versions include all supported Windows 10, Windows 11, and Windows Server editions. Open Settings → Windows Update and click “Check for updates.” On Windows 10, look for KB5120249; on Windows 11, look for KB5121003 or KB5120240 depending on your build. Enterprise environments managed through Windows Server Update Services (WSUS) or Microsoft Endpoint Manager should see these updates appear in their consoles today. CVE-2026-68820 is present in all unpatched versions of Windows with WinSock support, which effectively means every current Windows device.

Sources

Related reading