Microsoft on August 11 released 421 patches affecting 29 product families. Sixty-four of the addressed issues are considered by Microsoft to be of Critical severity; 35 CVEs are expected to be exploited within the next 30 days. (One already is; CVE-2026-68820 is an Important-severity Elevation of Privilege issue affecting most versions of Windows.) Eighty have a CVSS Base score of 8.0 or higher. Just one was publicly disclosed (but not yet exploited) as of release day, with one additional item (CVE-2026-69414) stated by Microsoft to be publicly disclosed by week’s end. (More on post-Tuesday patch activity in a moment.) One other, CVE-2026-68820, is acknowledged to be under active exploit in the wild.
In this AI-driven era, the relatively low count of advisories is striking. There are two MITRE-credited items (CVE-2026-6726, CVE-2026-6727) that were patched earlier in the month, but as these are Windows-related we’re simply rolling them into the main patch count. As for Edge, there were just 42 advisories (all but two issued by Chrome, not Microsoft), with everything patched in advance of Tuesday. There were also 24 updates issued by Adobe, affecting Commerce and ColdFusion.
Of greater interest is the remarkable number of very nasty bugs that were also patched earlier in the month. Nineteen vulnerabilities affecting 10 families have already been mitigated, and a twentieth (CVE-2026-24301, a Copilot Web issue) was handled several days later. The average CVSS Base score for those 20 is 9.3, with three weighing in at a “perfect” 10. In contrast, the average CVSS Base score for the rest of August’s patches is a less agita-inducing 7.2.
Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below.
AI-era trends we’ve been watching continue to develop. Once again we have a lot of multiple-finder vulnerabilities; CVE-2026-58612, an Important-severity PowerShell bug, leads the pack with 17 credited discoverers from around the globe. Anonymous is of course the busiest bee on the planet (every month), but the finder 0ccbbf129444eb66344ccafb92b00df4 topped the sheer-volume leaderboard for the second month, racking up 45 finds, all in 365 or Office (or both), 10 of Critical severity. For those who follow such things, there’s an interesting divide opening up between certain hyper-productive handles and certain well-known folk who are still producing finds at pre-AI volumes. We’re only five months into the era, but the trend bears watching.
Second, the rise in patch volume still isn’t translating to more bugs in the wild. The percentage of vulnerabilities Microsoft expects to be exploited in the wild within the next 30 days went up slightly in August (8.0 percent, compared to 7.7 percent for both June and July), but the number of bugs either publicly disclosed or under active exploit in the wild is vanishingly small – three, all together. In other words, so far the finders responsible for this flood are behaving, well, responsibly.
And what are they finding? We’ve now had Microsoft-provided CWE information for five months, which isn’t enough time to start opining on Where The Bugs Are, but we did notice that a different weakness type than usual is topping the CWE charts – CWE-122, better known as Heap-based Buffer Overflow or (if you think about CWEs a great deal, which… stop that) the perpetual runner-up to CWE-416, the ever-unpopular Use After Free. Over the course of the past five months these two have cumulatively accounted for just over a third of all flaws patched in Microsoft products. The second runner-up, CWE-125 (Out-of-bounds Read), doesn’t break ten percent of the cumulative total.
Oh. And we may have a pre-authentication, no-user-interaction-required, remote code execution problem for Windows, seven times over. Read on.
By the numbers
- Total CVEs: 421
- Publicly disclosed: 2
- Exploit detected: 1
- Severity
- Critical: 64
- Important: 356
- Moderate: 1
- Impact:
- Denial of Service: 12
- Elevation of Privilege: 177
- Information Disclosure: 86
- Remote Code Execution: 110
- Spoofing: 21
- Security Feature Bypass: 11
- Tampering: 4
- CVSS base score 9.0 or greater: 20
- CVSS base score 9.0 or greater, but patched in advance of Patch Tuesday: 13
- C VSS base score 9.0 or greater, but patched just after: 1
- CVSS base score 8.0 or greater: 80
Figure 1: As we have seen in previous months, Spoofing, Denial of Service, Security Feature Bypass, and Tampering vulnerabilities are not being found with substantially greater frequency in the AI era.
Products
- .NET: 12
- 365: 90
- Access: 5
- App Installer: 1
- Application Insights Profiler: 1
- Azure: 11
- Azure SQL: 2
- Copilot: 1
- Dynamics 365: 3
- Entra: 3
- Excel: 25
- Exchange: 7
- MMPC: 2
- Office: 89
- OneDrive: 1
- Outlook: 3
- Planetary Computer: 1
- Power Apps: 1
- Power BI: 1
- PowerPoint: 1
- PowerShell: 4
- Purview: 1
- SharePoint: 30
- Teams: 6
- Visual Studio: 18
- Win App Client /Desktop: 2
- Windows: 231
- Word: 16
As is our custom for this list, CVEs that apply to more than one product family are counted once for each family they affect.
Figure 2: Once again, Windows’ 231 CVEs – 18 Critical, 212 Important, one Moderate – are relegated to this caption. As we did last month, single-CVE families are also excluded for readability; please see the accompanying Excel file for details. Beyond that, 365 leads the pack with 90 patches, followed immediately by Office with 89. (The sole differentiator between Office and 365, CVE-2026-62873, is among the group for which patches were issued in advance of Patch Tuesday.)
Figure 3: Two-thirds of the way through the year, Elevation of Privilege issues continue to dominate.
Notable August updates
In addition to the issues discussed above, a few items merit general attention.
CVE-2026-62815 -- Microsoft QUIC Remote Code Execution Vulnerability
CVE-2026-62819 -- Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-62878 -- Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-62893 -- Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
CVE-2026-65789 -- Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-65791 -- Windows iSCSI Target Service Remote Code Execution Vulnerability
CVE-2026-66802 -- Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
All seven of these Critical-severity Windows CVEs require neither authentication nor user interaction – an attacker sends the malicious bits to the target and it’s off to the races. The most significant of the bunch is likely CVE-2026-62893, which Microsoft deems more likely to be exploited within the next 30 days.
CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317
(17 Office CVEs)
Preview Pane is a vector for all 17 of these Office CVEs. All but seven (CVE-2026-63517, CVE-2026-63524, CVE-2026-63529, CVE-2026-63533, CVE-2026-64899, CVE-2026-70315, CVE-2026-70317) are Critical-severity, though none are considered by Microsoft to be more likely to be exploited within the next 30 days.
CVE-2026-68820 -- Windows Elevation of Privilege Vulnerability
The only issue in this month’s release that Microsoft acknowledges as being under active exploit in the wild is an Important-severity Elevation of Privilege bug affecting most versions of Windows. This one would likely be exploited as part of a larger attack chain – the attacker would need to run a specially crafted application already on the targeted system. The outcome is local privilege elevation. It’s less dramatic on paper than the seven Critical remote-code-execution bugs or even this month’s Preview Pane haul, but exploit-detected is exploit-detected. Sophos Intercept X / Endpoint IPS and XGS Firewall both detect attempts against it as Exp/2668820-A.
CVE-2026-24301 – Microsoft Copilot Information Disclosure Vulnerability
CVE-2026-69414 – Microsoft Defender Elevation of Privilege Vulnerability
In a departure from our usual process, we’re using the Patch Tuesday post this month to talk about two vulnerabilities addressed several days after the main event. The Copilot vulnerability, a Critical-severity Information Disclosure issue, is a Cloud Service CVE and thus has no action item for customers – by the time anyone knew it was coming, it was already patched. The CVE-2026-69414 issue, on the other hand, caused a small stir when its finder – the “Nightmare Eclipse” persona who stirred up additional disclosure excitement earlier in the summer – dropped the Defender-targeting vuln and called it “ShieldBreak.” Microsoft has described this Important-severity Elevation of Privilege issue as a variant of CVE-2026-70307. Sophos customers have a relevant protection in place (Exp/2650656-A), and a full patch from Microsoft is expected very soon.
CVE-2026-63508 -- Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
Every so often, as we read and re-read the available Patch Tuesday information, we see a product name that startles us. So it is with this CVSS Base-10 CVE, for a product that may sound a bit creepy but is simply a newish tool (released in June) for interested parties to ingest and work with geospatial data. As a Cloud Services CVE issue, it is in any case already patched at this writing.
Sophos protections
| CVE | Sophos Intercept X/Endpoint IPS | Sophos XGS Firewall |
| CVE-2026-61348 | Exp/2661348-A | Exp/2661348-A |
| CVE-2026-61358 | Exp/2661358-A | Exp/2661358-A |
| CVE-2026-61359 | Exp/2661359-A | Exp/2661359-A |
| CVE-2026-61929 | Exp/2661929-A | Exp/2661929-A |
| CVE-2026-61930 | Exp/2661930-A | Exp/2661930-A |
| CVE-2026-62688 | Exp/2662688-A | Exp/2662688-A |
| CVE-2026-62698 | Exp/2662698-A | Exp/2662698-A |
| CVE-2026-62713 | Exp/2662713-A | Exp/2662713-A |
| CVE-2026-62888 | Exp/2662888-A | Exp/2662888-A |
| CVE-2026-62893 | sid:2312878 | sid:2312878 |
| CVE-2026-63520 | sid:2312881, sid:2312882 | sid:2312881, sid:2312882 |
| CVE-2026-65665 | sid:2312887 | sid:2312887 |
| CVE-2026-65775 | Exp/2665775-A | Exp/2665775-A |
| CVE-2026-65788 | Exp/2665788-A | Exp/2665788-A |
| CVE-2026-66804 | Exp/2666804-A | Exp/2666804-A |
| CVE-2026-68820 | Exp/2668820-A | Exp/2668820-A |
As you can every month, if you don’t want to wait for your system to pull down Microsoft’s updates itself, you can download them manually from the Windows Update Catalog website. Run the winver.exe tool to determine which build of Windows you’re running, then download the Cumulative Update package for your specific system’s architecture and build number.
Appendix: PatchTuesday_August2026
Once again we are dropping the mile-long appendices and present to you all the data you crave in a far more civilized format – an Excel workbook. You’ll find all your favorite appendix data there, in a format that allows readers to pivot and sort to their hearts’ content. The workbook contains multiple sheets:
PT_Summary – key monthly metrics in a single-screen format
PT_PriSevImp – best for sorting by impact, Microsoft-assigned severity / CVSS, impact, and prospects for exploitability
PT_ByProduct – a more granular breakdown focusing on product families; helpful when dealing with CVEs with multi-family applicability
PT_Windows – a chart showing which versions of Windows are affected by each patched CVE
PT_Protections – a list of all Sophos-issued protections applicable to this month’s patches; replicates the chart in the blog post for easy reference
PT_Advisories – a Service Stack notice along with information on Abode and Edge patches; as noted above, two MITRE-released Windows fixes are rolled instead into the main portion of our coverage
PT_CWE – a breakdown of which vulnerabilities were most often discovered in the products patched in August