August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft released fixes for 421 CVEs in its August 2026 Patch Tuesday, including CVE-2026-68820, a zero-day in afd.sys that attackers are using to gain SYSTEM privileges. The update also addresses several publicly disclosed local privilege escalation and remote code execution issues across Windows, Exchange Server, and other Microsoft products. #CVE-2026-68820 #afd.sys #CVE-2026-62832 #unionfs.sys #WindowsDNSServer #MicrosoftQUIC #ExchangeServer #TPM20

Keypoints

  • Microsoft patched 421 CVEs in its August 2026 security update.
  • CVE-2026-68820 is a zero-day use-after-free flaw in afd.sys exploited in the wild.
  • The afd.sys bug can let a locally authenticated attacker gain SYSTEM privileges.
  • CVE-2026-62832 in Windows User Profile Service may allow local privilege escalation and is publicly disclosed.
  • Microsoft also fixed RCE issues in Windows DNS Server, WDS TFTP, Microsoft QUIC, and Exchange Server.

Read More: https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/