Security updates address critical privilege escalation and remote code execution flaws across Microsoft's software portfolio.
Key Takeaways:
Microsoft has released the August 2026 Patch Tuesday updates for Windows 11. This month, the company fixed 398 vulnerabilities in Windows, Microsoft Office, Azure, Exchange Server, SharePoint, Teams, Power BI, .NET, Visual Studio and other products.
Microsoft is reminding customers that Windows 11 version 24H2 Home and Pro editions will reach end of support on October 13, 2026. After this date, these devices will no longer receive fixes for known issues, time zone updates, technical support, or monthly security and preview updates. However, Microsoft plans to support enterprise and education editions until October 12, 2027.
As pointed out by the Zero Day Initiative, Microsoft has released a total of 398 security patches, with fixes for 62 critical vulnerabilities. The company says one of them is rated Moderate and the rest are rated Important in severity. Here are the most important vulnerabilities you should know about this month:
Here’s the full summary of CVEs Microsoft released this month:
| Product Family | Updates per Product/Version | Vulnerabilities Addressed | Distinct Updates | Type of Update |
| Azure | 1 | 17 | 15 | Individual |
| Defender | 1 | 1 | 1 | Cumulative |
| Developer Tools | 1 | 26 | 36 | Cumulative |
| Exchange Server | 1 | 7 | 4 | Cumulative |
| Office | 1 | 98 | 11 | Cumulative (except 2016) |
| Office 2016 | 1 | 98 | 18 | Individual |
| Other | 1 | 6 | 4 | Individual |
| SharePoint Server | 1 | 30 | 3 | Cumulative |
| Windows | 1 | 236 | 32 | Cumulative |
For Windows version 26H1, the KB5121000 update improves TPM maintenance reporting by ensuring that EK certificate status is reported accurately. This patch also includes additional high-confidence device targeting data, which increases coverage of devices eligible to automatically receive new Secure Boot certificates.
Microsoft has rolled out the KB5121003 update for Windows 11 versions 25H2 and 24H2. This patch brings peripheral fingerprint sensor support for Windows Hello Enhanced Sign-in Security (ESS). Moreover, it improves the calculation of update progress in Windows Update Settings. This update also enhances clean-up logic to optimize system performance after installing an update on Windows machines.
Organizations looking to deploy this month’s patches should conduct thorough testing before deploying them widely on production systems. That said, applying the patches widely shouldn’t be delayed longer than necessary as hackers start to work out how to weaponize newly reported vulnerabilities.
A best practice is to make sure you have backed up systems before applying updates. Every month, users experience issues with Windows updates that lead to systems not booting, application and hardware compatibility issues, or even data loss in extreme cases.
There are backup tools built into Windows and Windows Server that you can use to restore systems in the event a patch causes a problem. The backup features in Windows can be used to restore an entire system, or files and folders on a granular basis.