Notebookcheck Logo

August 2026 Patch Tuesday: Microsoft fixes over 420 flaws

The official desktop user interface for Microsoft Windows 11.
ⓘ Microsoft.com
The official desktop user interface for Microsoft Windows 11.
A Windows kernel flaw was already being exploited by Lazarus hackers before Microsoft's August patch shipped. See which CVEs to prioritize this Patch Tuesday.

Microsoft's August 2026 Patch Tuesday has landed as one of the year's largest security updates, closing out 421 CVEs, including more than 40 rated critical, according to Microsoft's Security Update Guide and multiple security vendors tracking the release. The update is headlined by an actively exploited kernel driver flaw, a publicly disclosed elevation-of-privilege bug tied to a researcher long at odds with Microsoft, and a SharePoint remote code execution chain flagged by Rapid7.

Lazarus Group exploits kernel driver zero-day

The most urgent fix is CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver underpinning the Windows Sockets API. Microsoft says a locally authenticated attacker can trigger a race condition through a specially crafted application to gain SYSTEM privileges without user interaction. Check Point Research reported that North Korea's Lazarus Group exploited the flaw as part of its Operation Dream Job campaign, using fake recruiter outreach and a trojanized PDF viewer to deploy Troy, a new backdoor, before escalating privileges and installing an updated version of its FudModule kernel-mode rootkit. The activity has focused on defense, aerospace, and aviation organizations across Europe, India, and Brazil. CISA has added CVE-2026-68820 to its Known Exploited Vulnerabilities catalog, with a remediation deadline of August 25.

A public feud over LegacyHive

Microsoft also patched CVE-2026-62832, an elevation-of-privilege flaw in the Windows User Profile Service. The bug lets an authenticated attacker who holds credentials for another local account force the service to load that account's registry hive, potentially an administrator's, granting unauthorized access to that data and administrator rights. Microsoft credited the discovery to an anonymous researcher, though the technical details match LegacyHive, a proof of concept the pseudonymous researcher Nightmare Eclipse published just hours after July's Patch Tuesday. Because working exploit code had already circulated publicly, Microsoft assessed the flaw as more likely to be exploited more broadly.

Rapid7 completes a SharePoint RCE chain

Rounding out the release is CVE-2026-63520, a SharePoint Server remote code execution vulnerability rooted in unsafe .NET type instantiation within Business Connectivity Services. Rapid7 disclosed it alongside Microsoft as the second half of an exploit chain built for Pwn2Own Berlin. Paired with CVE-2026-55040, the JWT authentication bypass Rapid7 disclosed in July, the two flaws let an unauthenticated attacker execute code on a vulnerable SharePoint server with the privileges of its service account without any credentials.

Google LogoAdd as a preferred source on Google
Mail Logo
static version load dynamic
Loading Comments
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > News > News Archive > Newsarchive 2026 08 > August 2026 Patch Tuesday: Microsoft fixes over 420 flaws
Darryl Linington, 2026-08-14 (Update: 2026-08-14)