August 2026 Patch Tuesday: Microsoft fixes over 420 flaws

Microsoft's August 2026 Patch Tuesday has landed as one of the year's largest security updates, closing out 421 CVEs, including more than 40 rated critical, according to Microsoft's Security Update Guide and multiple security vendors tracking the release. The update is headlined by an actively exploited kernel driver flaw, a publicly disclosed elevation-of-privilege bug tied to a researcher long at odds with Microsoft, and a SharePoint remote code execution chain flagged by Rapid7.
Lazarus Group exploits kernel driver zero-day
The most urgent fix is CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver underpinning the Windows Sockets API. Microsoft says a locally authenticated attacker can trigger a race condition through a specially crafted application to gain SYSTEM privileges without user interaction. Check Point Research reported that North Korea's Lazarus Group exploited the flaw as part of its Operation Dream Job campaign, using fake recruiter outreach and a trojanized PDF viewer to deploy Troy, a new backdoor, before escalating privileges and installing an updated version of its FudModule kernel-mode rootkit. The activity has focused on defense, aerospace, and aviation organizations across Europe, India, and Brazil. CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog, with a remediation deadline of August 25.
A public feud over LegacyHive
Microsoft also patched CVE-2026-62832, an elevation-of-privilege flaw in the Windows User Profile Service. The bug lets an authenticated attacker who holds credentials for another local account force the service to load that account's registry hive, potentially an administrator's, granting unauthorized access to that data and administrator rights. Microsoft credited the discovery to an anonymous researcher, though the technical details match LegacyHive, a proof of concept the pseudonymous researcher Nightmare Eclipse published just hours after July's Patch Tuesday. Because working exploit code had already circulated publicly, Microsoft assessed the flaw as more likely to be exploited more broadly.
Rapid7 completes a SharePoint RCE chain
Rounding out the release is CVE-2026-63520, a SharePoint Server remote code execution vulnerability rooted in unsafe .NET type instantiation within Business Connectivity Services. Rapid7 disclosed it alongside Microsoft as the second half of an exploit chain built for Pwn2Own Berlin. Paired with CVE-2026-55040, the JWT authentication bypass Rapid7 disclosed in July, the two flaws let an unauthenticated attacker execute code on a vulnerable SharePoint server with the privileges of its service account without any credentials.












