Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Op-Ed: Microsoft August Patch Tuesday reveals a whopping 421 vulnerabilities!

High-volume Patch Tuesdays are apparently here to stay, and this month most of them are in Windows.

user icon Adam Barnett, Lead Software Engineer at Rapid7 Wed, 12 Aug 2026
Op-Ed: Microsoft August Patch Tuesday reveals a whopping 421 vulnerabilities!

Microsoft is publishing 421 vulnerabilities on the August 2026 Patch Tuesday, including 236 vulnerabilities in Windows.

This is a lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever.

There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026, however.

 
 

Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these.

As usual, browser vulnerabilities are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.

Today sees the publication of CVE-2026-63520, a high-severity remote code execution in Microsoft SharePoint. Discovered by Rapid7 senior principal security researcher Stephen Fewer and published today in coordination with Microsoft, this vulnerability is the second in a pair of exploits that, when chained together, comprise a critical unauthenticated remote code execution vulnerability in a vulnerable SharePoint server.

Patches are available for SharePoint Server Subscription Edition, 2019, and 2016. Alongside today’s coordinated disclosure of CVE-2026-63520, Rapid7 has now published a detailed technical analysis and proof of concept for CVE-2026-55040, the first vulnerability in the chain.

Rapid7 has previously discussed the Windows Ancillary Function Driver for WinSock, and today it returns to centre stage with another exploited-in-the-wild elevation-of-privilege vulnerability. Successful exploitation requires winning a race condition, which increases the difficulty of producing a stable exploit. This also helps keep the CVSS v3 base score down to 7.0, along with a Microsoft proprietary severity ranking of merely important, rather than critical. However, with no user interaction required and a prize of SYSTEM-level access, CVE-2026-68820 is just what the doctor ordered, if the doctor is based in Pyongyang and wants to steal your cryptocurrency.

Microsoft credits CVE-2026-68820 to researchers at Check Point (misspelled “Checkpoint” on the advisory). CVE-2026-68820 isn’t yet listed on CISA KEV, but it will be soon.

This month’s entry in the ongoing saga of Microsoft versus a pseudonymous security researcher with a clear dislike of Microsoft comes in the form of CVE-2026-62832, an elevation of privilege vulnerability in the Windows User Profile Service. Exploitation leads to administrator rights on the local asset and is achieved via a specially crafted application, which is Microsoft corporate argot for exploit code.

Between the public disclosure and the FAQ, which describes an authenticated attacker who has credentials for another account and loads another user’s registry hive, the advisory is a solid match for Nightmare Eclipse’s description of LegacyHive, which Rapid7 discussed last month.

Patch Tuesday watchers will have been wondering whether Nightmare Eclipse would continue the pattern of the past few months by dropping yet another zero-day vulnerability late on Patch Tuesday to maximise friction and inconvenience for Microsoft. Wonder no more, because the new entry on this growing list of headaches is ShieldBreak.

Nightmare Eclipse describes ShieldBreak as a full patch bypass for RoguePlanet, a previous entry in the series, which Microsoft patched as CVE-2026-50656 in July, a month after its public disclosure. Both vulnerabilities are therefore elevation-of-privilege to SYSTEM vulnerabilities in Defender.

CVE-2026-72971 describes a tampering vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys), where abuse of a flaw in the vulnerable driver presumably allows an unauthorised attacker to overwrite certain files. Since this might include an action taken within a container leading to an unauthorised impact outside the container, it might be surprising that the advisory claims no scope change.

Presumably, Microsoft is leaning on the fact that the vulnerability is within a driver that operates entirely within a single security authority, i.e., kernel space, so there is only one impacted component and no scope change according to the CVSS v3 spec. Still, the low CVSS v3 base score of 5.5 probably isn’t telling the whole story in this case.

Vulnerabilities classed as tampering are somewhat rare in the Microsoft corpus, making up just a few dozen of the thousands of unique vulnerabilities that MSRC has ever patched or otherwise addressed. CVE-2026-72971 isn’t mentioned in the Notable CVEs section of the new slimline Security Update Guide. Should it be? Perhaps, because Microsoft is aware of public disclosure in this case, but then again, the categorisation as tampering means that Microsoft is not currently aware of a path to a more severe impact, such as elevation of privilege or code execution.

The advisory acknowledges a pair of pseudonymous reporters, who also receive credit on at least 40 other advisories over the past few months, across a wide variety of Windows components and Microsoft Office, including 11 critical vulnerabilities.

Typically, Microsoft patches a fair few browser vulnerabilities between the start of each month and that month’s Patch Tuesday, but not this month. Conspicuous by its absence at the time of Patch Tuesday publication today was Microsoft Edge, which receives regular batches of patches as a downstream consumer of Google Chromium. At the moment of Patch Tuesday publication, the desktop incarnations of Edge last received security patches on 31 July 2026. Meanwhile, the Chrome Stable Channel received patches for 41 vulnerabilities on 6 August, 2026.

Anyone responsible for assets with Microsoft Edge installed will be relieved to know that patches for Edge eventually emerged a few hours later on Patch Tuesday itself, but five days is still a longer unpatched gap between Chrome and Edge than has been typical in the past.

August is typically a quieter month for Microsoft product life cycle transitions, and this year continues that pattern. The next life cycle changes with broad impact occur on 14 October 2026, when Windows 11 24H2 Home & Pro reach end of servicing, and Windows Server 2022 moves to extended support, with free critical security updates continuing, but no further feature development.

At the same time, the final curtain falls for Windows Server 2012 and 2012 R2 with the expiry of the third and final year of cash-for-updates Extended Security Update (ESU) program for these aging workhorses.

Office 2021 also moves beyond support, including the Long-Term Servicing Channel, with no ESU available in that case. Also in October, Exchange Server 2016 and 2019 will join the “no ESU” club, after two previous six-month reprieves.

Presumably, Microsoft really means it this time.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: