Microsoft’s August 2026 Patch Tuesday Addresses 62 Critical Vulnerabilities

Security updates address critical privilege escalation and remote code execution flaws across Microsoft's software portfolio.

Windows Logo

Key Takeaways:

  • Microsoft patched 398 vulnerabilities in August 2026, including 62 rated Critical.
  • The release fixes high-severity flaws affecting Windows, Exchange Server, Azure AD, and Entra services.
  • Windows 11 updates add ESS support for fingerprint sensors and improve update management capabilities.

Microsoft has released the August 2026 Patch Tuesday updates for Windows 11. This month, the company fixed 398 vulnerabilities in Windows, Microsoft Office, Azure, Exchange Server, SharePoint, Teams, Power BI, .NET, Visual Studio and other products.

Microsoft is reminding customers that Windows 11 version 24H2 Home and Pro editions will reach end of support on October 13, 2026. After this date, these devices will no longer receive fixes for known issues, time zone updates, technical support, or monthly security and preview updates. However, Microsoft plans to support enterprise and education editions until October 12, 2027.

August 2026 Patch Tuesday updates fix over 60 critical vulnerabilities

As pointed out by the Zero Day Initiative, Microsoft has released a total of 398 security patches, with fixes for 62 critical vulnerabilities. The company says one of them is rated Moderate and the rest are rated Important in severity. Here are the most important vulnerabilities you should know about this month:

  • CVE-2026-68820: This is an elevation of privilege (EoP) vulnerability in Windows Ancillary Function Driver for WinSock. This zero-day bug allows a locally authenticated attacker to gain SYSTEM-level access on affected systems.
  • CVE-2026-62832: This is another elevation-of-privilege vulnerability that affects the Windows User Profile Service. It could allow an unauthenticated local attacker with credentials for another local account to run a specially crafted application as well as potentially access/modify data and gain administrator privileges.
  • CVE-2026-62878: This is a 9.8-rated remote code execution (RCE) vulnerability in Windows DNS Server that doesn’t require any user interaction.
  • CVE-2026-62893: This is a critical vulnerability in Windows Deployment Services TFTP Server that leads to remote code execution without user authentication/interaction.
  • CVE-2026-62911: This Exchange flaw allows a privilege escalation through an authentication bypass. It could be exploited by an attacker to take over the mailboxes of all Exchange users, send or read emails, and download attachments.
  • CVE-2026-50481: This is a 9.9-rated elevation-of-privilege flaw that affects Microsoft Entra ID (Formerly Azure Active Directory). It involves modification of data that should be treated as immutable and could allow an already authorized attacker to elevate privileges over the enterprise network.
  • CVE-2026-59115: This is a 9.9-rated path traversal vulnerability that affects the Microsoft Entra Provisioning Service. It could allow an authorized attacker with low privileges to elevate privileges over an enterprise network.

Here’s the full summary of CVEs Microsoft released this month:

Product FamilyUpdates per Product/VersionVulnerabilities AddressedDistinct UpdatesType of Update
Azure11715Individual
Defender111Cumulative
Developer Tools12636Cumulative
Exchange Server174Cumulative
Office19811Cumulative (except 2016)
Office 201619818Individual
Other164Individual
SharePoint Server1303Cumulative
Windows123632Cumulative

Quality and experience updates

For Windows version 26H1, the KB5121000 update improves TPM maintenance reporting by ensuring that EK certificate status is reported accurately. This patch also includes additional high-confidence device targeting data, which increases coverage of devices eligible to automatically receive new Secure Boot certificates.

Microsoft has rolled out the KB5121003 update for Windows 11 versions 25H2 and 24H2. This patch brings peripheral fingerprint sensor support for Windows Hello Enhanced Sign-in Security (ESS). Moreover, it improves the calculation of update progress in Windows Update Settings. This update also enhances clean-up logic to optimize system performance after installing an update on Windows machines.

Windows Update testing and best practices

Organizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary as hackers start to work out how to weaponize newly reported vulnerabilities.

A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.

There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system, or files and folders on a granular basis.