Microsoft released the August 2026 Patch Tuesday update to close 421 security vulnerabilities across Windows systems. This release matters because it addresses critical flaws that attackers are actively exploiting right now. Users who delay installation leave their devices exposed to immediate threats from known attack vectors.
August update closes 421 vulnerabilities including active North Korean attacks
The update targets core Windows components and related server software. It fixes a critical zero-day in the Windows Ancillary Function Driver for WinSock (afd.sys). Microsoft also patched an elevation-of-privilege bug in the Windows User Profile Service. SharePoint Server received a fix for a remote code execution vulnerability.
Check Point Research identified that the afd.sys flaw, CVE-2026-68820, is being actively exploited by North Korea's Lazarus Group. The group is using this vulnerability in its 'Operation Dream Job' campaign to target specific users. Rapid7 disclosed the SharePoint Server flaw, CVE-2026-63520, as part of a Pwn2Own Berlin exploit chain. Researcher Nightmare Eclipse also released a proof-of-concept for the Windows User Profile Service bug, CVE-2026-62832.
More than 40 of the 421 fixed vulnerabilities are rated critical by Microsoft. These critical flaws allow attackers to gain high-level access or execute code remotely. The patch includes fixes for various other issues not rated as critical but still posing risks. CISA listed this update as part of their recommended security actions for federal systems.
We looked at the last Windows update while tracking these security themes. That previous patch focused on balance and stability improvements for hardware integration. This month's release prioritizes active threat mitigation over feature additions. Organizations should verify that their SharePoint and Windows endpoints are patched immediately.
Source: NotebookCheck




Discussion
0 comments