Microsoft has rolled out its August Patch Tuesday, delivering security updates that address a staggering 398 new vulnerabilities across its product ecosystem. Of these, 42 are classified as critical, with the vast majority of the remainder rated as high risk. The update impacts Windows, Office, Teams, Exchange Server, Hyper-V, Windows Defender, Visual Studio, and Azure cloud services. Notably, one Windows flaw is already being actively exploited in the wild, while two others were disclosed publicly before the patches were ready. According to the Windows Insider Blog, the next scheduled Patch Tuesday will arrive on September 8th, 2026.
August Patch Tuesday: Windows Security Updates
Over 200 of the patched vulnerabilities target various Windows versions, including Windows 10, Windows 11, and Windows Server. While Windows 10 support officially ended in October 2025, devices enrolled in the Extended Security Updates (ESU) program will continue receiving security patches until October 2027.

The most urgent issue in this month’s release is a use-after-free (UAF) vulnerability in the Windows auxiliary function driver for Winsock, tracked as CVE-2026-68820. Microsoft confirmed via the Windows Insider Blog that this flaw is currently being weaponized by threat actors. Although it requires pairing with a separate remote code execution (RCE) vulnerability to fully exploit, it grants attackers the ability to escalate privileges and execute code with system-level access. In practice, this means environments relying on Winsock for network communication are at immediate risk until the patch is deployed.
Among the 18 Windows vulnerabilities classified as critical, several stand out for their potential impact. CVE-2026-62878 is an RCE flaw in the Windows DNS server that leverages a buffer overflow to execute code with elevated privileges without any user interaction. Similarly, CVE-2026-62893 affects the Trivial File Transfer Protocol (TFTP) server within Windows Deployment Services, allowing code injection via UDP port 69 without user prompts. Admins managing deployment fleets should verify that TFTP services are restricted to internal networks where possible.
Additionally, Microsoft addressed RCE vulnerabilities in Quick UDP Internet Connections (QUIC), specifically CVE-2026-62815 and CVE-2026-59124. While the former is rated high risk and the latter isn’t considered critical because Microsoft’s High Performance Computing (HPC) Pack isn’t enabled by default, both allow attackers to execute injected code without user interaction. Even if HPC Pack is disabled, network-level monitoring remains a prudent defense.
Microsoft Office Security Updates
Microsoft Office received patches for 128 security vulnerabilities, including 22 critical RCE flaws. A significant portion of these critical issues reside in the Office graphics component. For enterprise environments, this is particularly concerning because the preview pane often serves as the attack vector. In many cases, users do not need to actually open a malicious file for the exploit to trigger.
Beyond the critical RCEs, the update also resolves high-risk vulnerabilities that require a user to open a malicious Office file directly (open-and-own). While this lowers the immediate threat surface, it still underscores the importance of maintaining strict email filtering and user awareness training.
Exchange Server and Edge Updates
Exchange Server administrators should pay close attention to seven newly patched vulnerabilities. The most severe is a critical elevation of privilege (EoP) flaw, CVE-2026-62911. Its exploitability was successfully demonstrated in May at the Pwn2Own hacking competition in Berlin. If leveraged, an attacker could bypass user authentication entirely, taking control of all email accounts, sending and receiving messages, and downloading attachments.

The remaining six Exchange vulnerabilities are classified as high risk, including RCE flaw CVE-2026-62913. Meanwhile, Microsoft Edge received a security update to version 151.0.4129.78, built on Chromium 151.0.7922.109. This update closes 41 Chromium vulnerabilities. These 41 issues are separate from the 398 total counted in this month’s Patch Tuesday report. A subsequent Chrome/Chromium update addressing five additional vulnerabilities is expected later this week.
What This Means for You
With an active exploit targeting Winsock and critical flaws in DNS and Exchange Server, delaying updates is no longer an option. Home users should run Windows Update immediately to patch the OS and Edge. Office 365 and perpetual license users should check for updates within the respective applications. Exchange Server admins must prioritize patching CVE-2026-62911 given its public demonstration at Pwn2Own.
For those running Windows 10 under the ESU program, these patches are essential for maintaining security through October 2027. If you haven’t already reviewed your vulnerability management policies, now is the time to ensure your deployment pipelines are configured to push these updates without unnecessary delays. Network segmentation and conditional access policies should also be audited to mitigate the risk of the demonstrated Exchange Server exploit.
Source: PCWorld
Over to you: Have you already applied the August patches to your Exchange servers, or are you waiting for the September update?



