Microsoft's August 2026 Patch Tuesday addresses 398 CVEs across a wide range of Windows components and Microsoft products. Of these, 42 are rated critical and 355 important. Three zero-days are included: CVE-2026-68820 (Windows Ancillary Function Driver for WinSock EoP, CVSS 7.0) was exploited in the wild; CVE-2026-62832 (Windows User Profile Service EoP, CVSS 7.8) and CVE-2026-72971 (Windows Container Isolation FS Filter Driver tampering) were publicly disclosed before patching. Notable critical flaws include CVE-2026-62893 (Windows Deployment Services TFTP Server RCE, CVSS 9.8) and CVE-2026-62823 (Windows DHCP Server RCE, CVSS 8.8). SharePoint received 29 patches, three rated critical. Elevation of Privilege vulnerabilities made up 40.7% of this month's patches, followed by RCE at 27.1%.
Table of contents
CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVE-2026-62832 | Windows User Profile Service Elevation of Privilege VulnerabilityCVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering VulnerabilityCVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution VulnerabilityCVE-2026-62823 | Windows DHCP Server Remote Code Execution VulnerabilityMultiple CVEs | Microsoft Office SharePoint Spoofing, Remote Code Execution, Elevation of Privilege, Information Disclosure and Tampering VulnerabilitiesTenable SolutionsQuestions this post answers
What is CVE-2026-68820 and was it exploited in the wild?
CVE-2026-68820 is an Elevation of Privilege vulnerability in the Windows Ancillary Function Driver for WinSock with a CVSSv3 score of 7.0, rated important. A local attacker can exploit it to gain SYSTEM privileges. Microsoft confirmed it was exploited in the wild as a zero-day in the August 2026 Patch Tuesday release. Two related EoP flaws in the same driver, CVE-2026-61348 and CVE-2026-70307, were also patched but not yet exploited. Windows defenders tracking actively exploited zero-days keep up with disclosures like this on daily.dev.
How severe is CVE-2026-62893 in Windows Deployment Services and how can it be exploited?
CVE-2026-62893 is a critical RCE vulnerability in the Windows Deployment Services TFTP Server with a CVSSv3 score of 9.8. A remote, unauthenticated attacker can exploit it by sending crafted packets to the vulnerable service, resulting in arbitrary code execution. Microsoft assessed it as 'Exploitation More Likely.' It was reported by Nikolai Skliarenko of TrendAI Research and patched in August 2026. Teams running Windows Deployment Services can track patch urgency for critical RCE flaws like this on daily.dev.
How many CVEs did Microsoft patch in August 2026 Patch Tuesday and what types dominated?
Microsoft patched 398 CVEs in August 2026 Patch Tuesday: 42 rated critical, 355 important, and 1 moderate. Elevation of Privilege vulnerabilities were the most common type at 40.7% of all patches, followed by Remote Code Execution at 27.1%. Three zero-days were included, one of which was actively exploited in the wild. Staying on top of monthly patch volumes and vulnerability trends is easier when the security community discusses them on daily.dev.