Safeguard
Vulnerabilities

Patch Tuesday August 2026: ~398 Flaws, 3 Zero-Days, and One the Norks Already Used

Microsoft shipped fixes for roughly 398 CVEs on 11 August. Three are zero-days, one is under active exploitation by Lazarus, and the vendor tallies disagree by nearly 30.

Nayan Dey
Senior Security Engineer
6 min read

Microsoft released its August 2026 security updates on 11 August, covering Windows, Office, SharePoint Server, Azure services, .NET, PowerShell, and Visual Studio Code.

The working number is 398 CVEs, of which 42 are rated Critical, 355 Important, and one Moderate. Three are zero-days. One of those is being actively exploited, and it has already been tied to a named nation-state operation.

First, the counting problem

The vendor tallies do not agree. Tenable reports 398. BleepingComputer says 400. SecurityWeek and The Register both say 421. Other trackers land at 394.

This is the same methodology gap we flagged in the June roundup: outlets differ on whether to include republished Chromium CVEs for Edge, Azure and cloud-side fixes that required no customer action, Mariner/CBL container CVEs, and third-party advisories Microsoft rebroadcasts. Every one of those choices is defensible, and they compound into a 27-CVE spread.

We use 398 because it reconciles with the published severity breakdown — 42 + 355 + 1 lands exactly there. But the honest position is the one we argued yesterday in why enumeration stopped being a strategy: if four reputable trackers cannot agree on the denominator, no programme should be managed against it. Prioritise by exploitability. The count is a headline, not a metric.

The one being exploited

CVE-2026-68820 — a use-after-free in the Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver behind the Windows Sockets API. A locally authenticated attacker who wins a race condition in how the driver handles a socket accessed concurrently by multiple threads gains SYSTEM.

CVSS 7.0. It is the only flaw in this release Microsoft confirms is under active exploitation, and Check Point Research attributes its use to Lazarus in the Operation Dream Job campaign, deploying a new build of the FudModule kernel rootkit.

A 7.0 outranks all 42 Criticals in this release, because exploitation is observed rather than theoretical. We covered why exploitation status beats base score last week; this is the month's clean example. There is a fuller breakdown of the flaw and the campaign in our analysis of CVE-2026-68820.

The two publicly disclosed zero-days

CVE-2026-62832 was publicly disclosed before a fix existed. CVE-2026-72971 was publicly disclosed ahead of Patch Tuesday, and Microsoft states it has not been exploited.

Public disclosure without confirmed exploitation still matters. It compresses the interval between "researchers have details" and "attackers have working code" — and given that 88% of exploitation with a public PoC happens inside 48 hours, that interval is where your remaining margin lives.

The Critical block

Of the 42 Criticals, 37 are remote code execution and 5 are elevation of privilege.

That ratio should drive your sequencing. Nobody tests and deploys 398 patches in a day. The triage that holds up:

  1. CVE-2026-68820 first. Confirmed exploitation, nation-state tooling, SYSTEM.
  2. Critical RCE on anything internet-reachable. 37 candidates; the subset exposed to untrusted networks is much smaller and is your real second tier.
  3. The two disclosed zero-days, on the assumption exploit code follows disclosure.
  4. Everything else, on your normal cadence.

What is in the other 355

The Important-rated bulk is where most of the deployment effort actually goes, and it is worth knowing its shape before you plan the window.

The release spans Windows and its kernel-mode drivers, Office and SharePoint Server, Azure services, .NET, PowerShell, and Visual Studio Code. Two observations follow from that spread.

A meaningful share needs no action from you. Azure and other cloud-side fixes are frequently remediated by Microsoft in the service and appear in the Security Update Guide for transparency. They inflate the count without adding work — which is a large part of why the totals differ between trackers in the first place.

SharePoint Server and Office deserve attention out of proportion to their rating. Both process untrusted content by design and both sit at the boundary between the internet and an authenticated internal session. An Important-rated Office flaw reachable through a document a user was emailed is a more realistic intrusion path than a Critical on a service nothing can route to.

The general point: severity describes the flaw, not your exposure to it. A Critical on an internal-only service you have segmented is lower risk than an Important on the mail path every employee uses daily. Sorting the 355 by rating alone will put effort in the wrong place, and it is the default behaviour of most patch tooling.

Do not miss the SAP flaw

Landing the same day and easy to lose behind the Microsoft numbers: a maximum-severity SAP vulnerability.

This is a recurring failure mode. Patch Tuesday consumes the whole attention budget, and non-Microsoft advisories published in the same window get read a week late. If you run SAP, that advisory outranks most of this Microsoft release for you.

What to do this week

Deploy CVE-2026-68820 inside 24–48 hours on any system where a local foothold is plausible — which is every workstation and every multi-user server.

Do not defer it because it is "local only." That reasoning is how privilege-escalation flaws end up unpatched for months. Local access is the cheap part of a modern intrusion; phishing, a malicious package, or a compromised dependency all supply it.

Check the SAP advisory separately, outside the Patch Tuesday workflow.

Stop reporting the CVE count to leadership as a risk measure. Report what is exploited, what is reachable, and what you patched. Given the 27-CVE spread across trackers, the total is not a number you can defend anyway.

How Safeguard helps

Prioritisation by exploitation and reachability rather than by count. Safeguard combines KEV membership, EPSS, public exploit availability, network exposure, and code-level reachability, so the one exploited 7.0 sorts above 42 Criticals automatically instead of after a triage meeting.

Inventory that spans vendors. The SAP advisory gets missed because it sits outside the Microsoft workflow. Safeguard's Supply Chain Core inventories operating systems, appliances, enterprise applications, containers, packages, and models in one continuous CycloneDX and SPDX record, so the month's advisories land in one queue.

Automatic re-ranking as facts change. A disclosed-but-unexploited zero-day like CVE-2026-72971 should escalate the day exploit code appears. Safeguard re-evaluates when the inputs change rather than at the next review cycle.

Griffin for the mechanical majority. Most of a 398-CVE month is version bumps and package updates across many systems. Griffin authors and tests those as reviewable pull requests in parallel.

If your August plan is "deploy the whole release this weekend," check first whether CVE-2026-68820 is in the first wave. It is the only one in the set that attackers are already using.

Sources: Tenable · BleepingComputer · SecurityWeek · The Register · The Hacker News · CSO Online · MSRC advisory

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.