Active Windows zero-day drives urgent August patch Tuesday across core services

Microsoft’s August Patch Tuesday closes 398 CVEs, including CVE-2026-68820—a use‑after‑free in afd.sys that can escalate from code execution to SYSTEM and is under active exploitation—making it the top priority; four other high‑severity flaws (CVE-2026-62878 in Windows DNS Server, CVE-2026-62893 in Windows Deployment Services, CVE-2026-62815 in Microsoft QUIC, and CVE-2026-59124 in HPC Pack) are unauthenticated RCEs whose exploitation depends on service exposure. The update also finishes a two‑part SharePoint chain (CVE-2026-55040 and CVE-2026-63520) first disclosed by Rapid7. Prioritize systems with exposed DNS/WDS/QUIC/HPC services and ensure on‑prem SharePoint farms apply both July and August fixes to close the chain.
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack The Hacker News
- Microsoft Plugs Nearly 400 Security Holes Krebs on Security
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day SecurityWeek
- 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one The Register
- Microsoft Releases August 2026 Patch Tuesday Updates Thurrott.com
Reading Insights
0
9
3 min
vs 4 min read
87%
727 → 97 words
Want the full story? Read the original article
Read on The Hacker News