Microsoft published fixes for 421 vulnerabilities on August 11, including 236 in Windows itself. One of them was already being exploited in attacks, two others were public knowledge before a patch existed, and on the same day a pseudonymous researcher released details of a Windows Defender flaw that Microsoft has not fixed at all.
It is a smaller batch than July's record 622, but still one of the largest monthly releases Microsoft has ever shipped, and Rapid7's Adam Barnett writes in the firm's monthly breakdown that there is no reason to expect a return to the lower volumes seen before 2026. Cisco Talos counts 62 vulnerabilities that Microsoft marked critical, 40 of which allow remote code execution.
The bug already under attack
The single flaw Microsoft says is being exploited in the wild is CVE-2026-68820, a use-after-free bug in the Windows Ancillary Function Driver for WinSock that hands a local attacker SYSTEM privileges, the highest level of access on a Windows machine. Microsoft credits it to researchers at Check Point, and its CVSS score of 7.0 is held down by the fact that an attacker has to win a race condition to exploit it reliably. We covered the campaign behind it yesterday: North Korea's Lazarus group burned it to switch off security tooling inside aerospace and defense companies.
A Defender flaw with no fix
The researcher known as Nightmare Eclipse, who has spent recent months publishing Windows zero-days on Patch Tuesday itself, marked this one with a release called ShieldBreak. Nightmare Eclipse describes it as a full bypass of the patch for RoguePlanet, an earlier Defender privilege escalation that Microsoft fixed in July as CVE-2026-50656, a month after it went public. Both are elevation of privilege flaws that end with SYSTEM access through Defender itself. There is no patch for ShieldBreak.
Two other bugs in this month's batch were publicly disclosed before release. CVE-2026-62832 is an elevation of privilege flaw in the Windows User Profile Service that yields administrator rights on the local machine, and Rapid7 assesses the advisory to be a solid match for LegacyHive, another Nightmare Eclipse disclosure. CVE-2026-72971 is a tampering flaw in the Windows Container Isolation FS Filter Driver, rated CVSS 5.5, which allows an attacker to overwrite certain files; Microsoft is not currently aware of a path from it to a more severe impact.
What to patch first
The highest-scored issues this month are in Microsoft's cloud services. CVE-2026-62830, an elevation of privilege flaw in the Azure SRE Agent caused by missing authorization, carries a CVSS score of 9.9, and CVE-2026-50516 in Azure Kubernetes Service scores 9.4 on missing authentication. On-premises, Microsoft rates exploitation "more likely" for CVE-2026-62893, a use-after-free in the Windows Deployment Services TFTP server that scores 9.8 and can be reached by an unauthenticated attacker over the network, and for two flaws at 8.8: CVE-2026-62823, a heap overflow in the Windows DHCP Server, and CVE-2026-65665, a deserialization bug in SharePoint Server.
SharePoint administrators have a second reason to move quickly. Microsoft also patched CVE-2026-63520, found by Rapid7 Senior Principal Security Researcher Stephen Fewer, which is the second half of an unauthenticated remote code execution chain. Rapid7 has now published its technical analysis and a proof of concept for the first half, CVE-2026-55040.
One oddity is worth a check on your own estate: Microsoft shipped no desktop browser patches ahead of Patch Tuesday this month. Edge, which inherits fixes from Google's Chromium, last received desktop security updates on July 31, while Chrome's stable channel took 41 fixes on August 6. Edge patches did emerge a few hours after Patch Tuesday, but that five-day gap behind Chrome is longer than has been typical.
Barnett also flags an October deadline worth planning for now. On October 14, Windows 11 24H2 Home and Pro reach end of servicing, Windows Server 2022 moves to extended support, and Office 2021 falls out of support. The same date ends the third and final year of paid Extended Security Updates for Windows Server 2012 and 2012 R2, and Exchange Server 2016 and 2019 lose their reprieve with no paid extension on offer.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.