CVE Tools

Microsoft Patch Tuesday August 2026 - SANS ISC

SANS Internet Storm CenterBy SANS Internet Storm Center

Reported exploitedWindowsQUIC

Our summary

Microsoft released patches for 418 vulnerabilities this month, addressing a mix of critical issues across its product ecosystem. The most pressing concern is CVE-2026-68820, a privilege escalation flaw in the Windows Ancillary Function Driver for WinSock that is currently being actively exploited in the wild. Additionally, two zero-days were publicly disclosed before release: CVE-2026-62832, affecting the Windows User Profile Service, and CVE-2026-72971, which impacts container isolation via the unionfs.sys driver. Administrators should also prioritize fixing remote code execution vulnerabilities in Microsoft QUIC (CVE-2026-62815) and Windows DNS Server (CVE-2026-62878), both rated Critical with high CVSS scores.

Read at SANS Internet Storm Center

SANS Internet Storm Center publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store