Microsoft has released its August 2026 Patch Tuesday, and IT administrators should brace themselves. This month’s security update is a monster release, closing a staggering 751 CVE entries across all product families, with 108 of those rated as critical. The most urgent concern is an actively exploited elevation of privilege flaw in the Windows WinSock driver, known as afd.sys. This means threat actors are already weaponizing this vulnerability in the wild, making immediate patching a top priority for all Windows environments.
Beyond the exploited flaw, two additional vulnerabilities have been disclosed but are not yet seen in active attacks: CVE-2026-62832 in the User Profile Service and CVE-2026-72971. While the lack of exploitation for these two offers a brief window, the sheer volume of critical updates across server roles like DHCP and DNS means there is no reason to delay deployment. This security-only release earns a “Patch Now” rating for Windows, Office, and Exchange, though notably, there are no SQL Server updates this month.
Exploited Flaw: WinSock Elevation of Privilege
The headline vulnerability in this month’s release is CVE-2026-68820, an elevation of privilege flaw located in the Windows WinSock driver (afd.sys). WinSock, or Windows Sockets, is the programming interface that allows applications to communicate over a network using TCP/IP. The afd.sys driver is fundamental to this process, handling the low-level socket operations that nearly every networked application relies on.
Because this driver is so deeply embedded in the Windows networking stack, an attacker who exploits this flaw can escalate their privileges from a standard user to system-level access. This is particularly dangerous because it can be triggered remotely, meaning an attacker could potentially gain control over a server or workstation without any physical interaction. The fact that this is already being exploited underscores the urgency of this update. Organizations should prioritize patching all Windows clients and servers, especially those exposed to the internet or untrusted networks, to close this gap immediately.
Known Issues and WSUS Sync
While the August updates are robust, there are a few known issues that administrators should be aware of before deploying. Both client and server-side updates ship with empty known-issues lists for new problems, which is a positive sign. However, legacy issues persist and require attention.
- Status: Confirmed / No Published Workaround
- Affected Versions: Windows Server 2025 (KB5120233) and Windows Server 2022 (KB5120242)
- Issue: WSUS Synchronization Error Details Suppressed
On the server side, the WSUS synchronization error details remain suppressed. This was a deliberate change to address a remote code execution flaw identified as CVE-2025-59287. The detail pane that previously showed specific error information has been removed to mitigate this risk. Currently, there is no published workaround for this suppression. If your WSUS servers are relying on those error details for troubleshooting, you may need to rely on alternative logging mechanisms or wait for Microsoft to provide a resolution that restores the details without exposing the vulnerability.
Additionally, one July item has been dropped from the documentation without a resolution note: the Windows Server 2022 BitLocker recovery prompt on first restart for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team strongly recommends that all recovery keys are easily retrievable before restarting freshly patched servers. This is a critical precaution to avoid being locked out of your servers during the reboot process.
Windows: DHCP and DNS Under Siege
Windows carries the bulk of this month’s vulnerabilities with 233 CVEs, 18 of which are rated as critical. The majority of these are elevation of privilege flaws, but the critical ones are predominantly remote code execution vulnerabilities targeting network-facing server roles. This makes DHCP and DNS the primary targets for attackers this month.
Windows DHCP Server is the most affected component, with 14 CVEs. The most significant of these is CVE-2026-62823, a critical remote code execution flaw rated as “Exploitation More Likely.” DHCP servers are often exposed to internal networks and can be targeted by attackers to gain a foothold. The DHCP Client also sees four additional entries, affecting the client-side experience. Windows DNS Server is the other major headline risk, with six entries, four of which are critical. These include CVE-2026-62878, CVE-2026-62817, CVE-2026-62820, and CVE-2026-65789, all of which are critical remote code execution flaws that reach back to Server 2012. DNS servers are critical infrastructure, and any compromise can lead to significant network disruption or data exfiltration.
Beyond DHCP and DNS, critical-rated issues also affect Microsoft QUIC, RRAS, the iSCSI Target Service, the WDS TFTP Server, the Remote Desktop Client, GDI+ graphics, and Active Directory Certificate Services. Domain controllers should be patched first, followed by DHCP and DNS servers. The Print Spooler and WSUS are absent from the critical list this month, which is a welcome relief for those components.
Office and SharePoint: Critical RCEs in the Wild
Microsoft Office sees 120 CVEs this month, with 24 rated as critical. Remote code execution is the through-line, accounting for 62 of these entries. The packaging work primarily involves MSI Office 2016 and SharePoint farms, but the exposure is overwhelmingly for Click-to-Run deployments.
Of the 120 Office CVEs, 89 list Microsoft 365 Apps for Enterprise as affected, with 20 of them being critical. This means Click-to-Run estates are squarely in scope. The top-rated critical client entry, CVE-2026-70130, affects Microsoft 365 Apps and involves document-rendering paths that fire on preview or open. This is particularly dangerous because it can be triggered simply by viewing a malicious document in the preview pane, without the user even opening the file.
SharePoint Server also faces three critical-rated vulnerabilities, led by CVE-2026-65665, an RCE rated “Exploitation More Likely” for SharePoint 2019 and Subscription Edition. This is followed by two critical elevation-of-privilege entries. A separate SharePoint Online spoofing flaw is fixed service-side. While nothing in Office is currently exploited, the presence of a critical SharePoint RCE and 20 Click-to-Run critical-rated vulnerabilities argues strongly against waiting. Add the August Office and SharePoint updates to your Patch Now schedule immediately.
Exchange Server: Seven CVEs, One Critical
On-premises Exchange Server receives a security update this month with seven CVEs across Exchange Server 2016, 2019, and Subscription Edition. These are addressed by four build-specific updates: KB5121573 through KB5121576. One of these is critical, and six are important, covering elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass.
The critical entry is an elevation of privilege flaw identified as CVE-2026-62911. The heaviest of the remaining issues is a remote code execution vulnerability, CVE-2026-62913. Although none of these are currently disclosed or exploited, Exchange is an internet-facing service, making it a prime target for attackers. It is crucial to apply this update from an elevated command prompt, as an un-elevated run leaves Exchange services partially patched and broken. After applying the update, confirm that every Exchange service returns and that the server reports healthy. Test mail flow end-to-end, including internal and external mail, transport queues, connectors, and transport rules. Also, verify Outlook (MAPI over HTTP), Outlook on the web, and the Exchange admin centre for sign-in and core actions. Confirm Autodiscover and free/busy resolve, and test any hybrid connection to Exchange Online. Plan for the required reboot and validate in a maintenance window before production.
Developer Tools: .NET and Visual Studio Code
Microsoft released 23 CVEs across its developer tooling this month, all rated as important. This includes 13 in .NET and the .NET Framework, and 10 across Visual Studio Code and its Copilot extensions.
The .NET ecosystem is the focus this month, with the runtime and framework being the primary targets. Two remote code execution entries lead the charge: CVE-2026-62897 for .NET Framework and CVE-2026-70354 for .NET Core. The Framework rollups span Windows Server 2012 to Windows 11 26H1 and Server 2025. Visual Studio 2022 17.14 and 2026 18.8 take their exposure through the bundled runtime. Visual Studio Code and Copilot have three remote code execution entries and security feature bypasses across the Python extension, Copilot Chat, and the core editor.
For developer estates, the recommendation is to add these updates to the standard release schedule, but behind the month’s Windows and Office priorities. Run a representative set of WPF, WinForms, web, and command-line applications to confirm normal behavior, and build and run a .NET project to check for regressions.
Adobe and Third-Party Vulnerabilities
Unusually, Adobe published an early-August emergency fix for a maximum-severity Adobe flaw, CVE-2026-48449, which is an incorrect authorization that runs code with no user interaction. This makes this an Adobe “whatever you have installed” Patch Now moment due to how Adobe tends to share code between products. Organizations should ensure all Adobe products are updated to mitigate this risk.
There were also two third-party flaws on Microsoft’s third-party list: the Trusted Computing Group’s TPM 2.0 reference-code bugs CVE-2026-6726 and CVE-2026-6727, both rated Important and issued by MITRE. If unpatched, a local attacker with TPM command access can work back to keys the chip should keep sealed, up to the RSA Endorsement Key behind device attestation. This completely defeats the purpose of the TPM chip and undermines the security foundations of Windows 11. These vulnerabilities highlight the importance of keeping TPM firmware and reference code up to date.
Testing Guidance: What to Check First
Given the volume and nature of this month’s updates, testing should be thorough. The Readiness team recommends the following priorities for your larger enterprise deployments:
- Start with printing and fonts: Three of the four High Risk flags sit in win32k, so regress 32-bit printing, PDF and XPS export, font rendering, and Print Preview before anything else. Pay attention to clipping, distortion, or missing glyphs.
- Take Remote Desktop next: The fourth High Risk flag affects the RDP client. Test across redirection paths, concurrent sessions, reconnects, RemoteApp, and SSTP VPN. Ensure redirected devices and drives reattach correctly.
- Give the busy but lower-risk areas a smoke pass: Telephony, the graphics kernel, DNS and DHCP, Active Directory, and the SMB stack. Exercise TAPI line status and dialling locations, and verify HTTP.sys under IIS over HTTP/1.1, HTTP/2, and HTTP/3.
- Close out the rest: Office spans MSI 2016, SharePoint, and Microsoft 365 Apps this month. .NET is a representative-application check. For storage, exercise SMB shares, NTFS extended attributes, and cloud-file hydrate and dehydrate. For virtualization, create, checkpoint, and export a Generation 2 Hyper-V VM with a virtual TPM and BitLocker.
Windows Lifecycle and Enforcement Updates
Microsoft has not published any service or enforcement deadlines for this August. However, the 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November. This is a critical period for lifecycle management.
- Windows Server 2012 and 2012 R2 ESU hits year three. Windows 10 2016 LTSB reaches the end of extended support, and Office LTSC 2021 and retail Office 2021 all end 13 October.
- Windows Server 2022 drops to extended support on 13 October 2026, with security-only support until 14 October 2031.
- Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, two Patch Tuesdays out.
This means organizations running older versions of Windows Server and Office need to have migration plans in place. The end of support for Windows 11 24H2 Home and Pro is particularly notable, as it signals the end of the line for these editions. Ensure you are on a supported version to continue receiving security updates.
What This Means for You
For everyday Windows users, the August 2026 Patch Tuesday is a reminder to keep your systems up to date. The exploited WinSock flaw means you could be at risk even if you are not actively clicking on suspicious links. Enable automatic updates if you haven’t already, or manually check for updates as soon as possible. For IT administrators, this is a high-priority month. Focus on DHCP and DNS servers first, followed by Office and Exchange. Test thoroughly, especially around printing and remote desktop functionalities. And don’t forget to check your Adobe products and TPM firmware. The volume of fixes is large, but the risks of inaction are even larger.
Source: Computerworld
Build details:
- KB5002755
- KB5002791
- KB5002795
- KB5002813
- KB5002832
- KB5002900
- KB5002901
Over to you: Are you prioritizing the DHCP and DNS server updates first, or focusing on the Office Click-to-Run fixes?



