Microsoft on August 11 released 423 patches affecting 28 product families. Sixty-three of the addressed issues are considered by Microsoft to be of Critical severity; 34 CVEs are expected to be exploited within the next 30 days. (One already is; CVE-2026-68820 is an Important-severity Elevation of Privilege issue affecting most versions of Windows.) Eighty-one have a CVSS Base score of 8.0 or higher. Just one was publicly disclosed (but not yet exploited) as of release day, One other, CVE-2026-68820, is acknowledged to be under active exploit in the wild.
The absence of advisories of any kind is striking. There are two MITRE-credited items (CVE-2026-6726, CVE-2026-6727) that were patched earlier in the month, but as these are Windows-related we’re simply rolling them into the main patch count. Of greater interest is the remarkable number of very nasty bugs that were also patched earlier in the month. Nineteen vulnerabilities affecting 10 families have already been mitigated; the average CVSS Base score for those 19 is 9.3, with three weighing in at a “perfect” 10. In contrast, the average CVSS Base score for the other 404 patches is a less agita-inducing 7.2.
Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below.
AI-era trends we’ve been watching continue to develop. Once again we have a lot of multiple-finder vulnerabilities; CVE-2026-58612, an Important-severity PowerShell bug, leads the pack with 17 credited discoverers from around the globe. Anonymous is of course the busiest bee on the planet (every month), but the finder 0ccbbf129444eb66344ccafb92b00df4 topped the sheer-volume leaderboard for the second month, racking up 45 finds, all in 365 or Office (or both), 10 of Critical severity. For those who follow such things, there’s an interesting divide opening up between certain hyper-productive handles and certain well-known folk who are still producing finds at pre-AI volumes. We’re only five months into the era, but the trend bears watching.
Second, the rise in patch volume still isn’t translating to more bugs in the wild. The percentage of vulnerabilities Microsoft expects to be exploited in the wild within the next 30 days went up slightly in August (8.0 percent, compared to 7.7 percent for both June and July), but the number of bugs either publicly disclosed or under active exploit in the wild is vanishingly small – one of each. In other words, so far the finders responsible for this flood are behaving, well, responsibly.
And what are they finding? We’ve now had Microsoft-provided CWE information for five months, which isn’t enough time to start opining on Where The Bugs Are, but we did notice that a different weakness type than usual is topping the CWE charts – CWE-122, better known as Heap-based Buffer Overflow or (if you think about CWEs a great deal, which… stop that) the perpetual runner-up to CWE-416, the ever-unpopular Use After Free. Over the course of the past five months these two have cumulatively accounted for just over a third of all flaws patched in Microsoft products. The second runner-up, CWE-125 (Out-of-bounds Read), doesn’t break ten percent of the cumulative total.
Oh. And we may have a pre-authentication, no-user-interaction-required, remote code execution problem for Windows, seven times over. Read on.
By the numbers
- Total CVEs: 423
- Publicly disclosed: 1
- Exploit detected: 1
- Severity
- Critical: 63
- Important: 359
- Moderate: 1
- Impact:
- Denial of Service: 13
- Elevation of Privilege: 177
- Information Disclosure: 85
- Remote Code Execution: 112
- Spoofing: 22
- Security Feature Bypass: 11
- Tampering: 3
- CVSS base score 9.0 or greater: 20
- CVSS base score 9.0 or greater, but patched in advance of Patch Tuesday: 13
- CVSS base score 8.0 or greater: 81

Figure 1: As we have seen in previous months, Spoofing, Denial of Service, Security Feature Bypass, and Tampering vulnerabilities are not being found with substantially greater frequency in the AI era.
Products
- .NET: 12
- 365: 90
- Access: 5
- App Installer: 1
- Application Insights Profiler: 1
- Azure: 11
- Azure SQL: 2
- Defender: 1
- Dynamics 365: 3
- Entra: 3
- Exchange: 7
- Excel: 25
- Office: 89
- OneDrive: 1
- Outlook: 3
- Planetary Computer: 1
- Power Apps: 1
- Power BI: 1
- PowerPoint: 1
- PowerShell: 4
- Purview: 1
- SharePoint: 30
- Teams: 6
- Visual Studio: 18
- Win App Client /Desktop: 2
- Windows: 233
- Windows Remote Help: 2
- Word: 16
As is our custom for this list, CVEs that apply to more than one product family are counted once for each family they affect.

Figure 2: Once again, Windows’ 233 CVEs – 18 Critical, 214 Important, one Moderate – are relegated to this caption. As we did last month, single-CVE families are also excluded for readability; please see the accompanying Excel file for details. Beyond that, 365 leads the pack with 90 patches, followed immediately by Office with 89. (The sole differentiator between Office and 365, CVE-2026-62873, is among the group for which patches were issued in advance of Patch Tuesday.)

Figure 3: Two-thirds of the way through the year, Elevation of Privilege issues continue to dominate.
Notable August updates
In addition to the issues discussed above, a few items merit general attention.
CVE-2026-62815 — Microsoft QUIC Remote Code Execution Vulnerability
CVE-2026-62819 — Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-62878 — Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-62893 — Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
CVE-2026-65789 — Windows DNS Server Remote Code Execution Vulnerability
CVE-2026-65791 — Windows iSCSI Target Service Remote Code Execution Vulnerability
CVE-2026-66802 — Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability
All seven of these Critical-severity Windows CVEs require neither authentication nor user interaction – an attacker sends the malicious bits to the target and it’s off to the races. The most significant of the bunch is likely CVE-2026-62893, which Microsoft deems more likely to be exploited within the next 30 days.
CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64909, CVE-2026-65657, CVE-2026-66807, CVE-2026-70315, CVE-2026-70317
(17 Office CVEs)
Preview Pane is a vector for all 17 of these Office CVEs. All but seven (CVE-2026-63517, CVE-2026-63524, CVE-2026-63529, CVE-2026-63533, CVE-2026-64899, CVE-2026-70315, CVE-2026-70317) are Critical-severity, though none are considered by Microsoft to be more likely to be exploited within the next 30 days.
CVE-2026-68820 — Windows Elevation of Privilege Vulnerability
The only issue in this month’s release that Microsoft acknowledges as being under active exploit in the wild is an Important-severity Elevation of Privilege bug affecting most versions of Windows. This one would likely be exploited as part of a larger attack chain – the attacker would need to run a specially crafted application already on the targeted system. The outcome is local privilege elevation. It’s less dramatic on paper than the seven Critical remote-code-execution bugs or even this month’s Preview Pane haul, but exploit-detected is exploit-detected. Sophos Intercept X / Endpoint IPS and XGS Firewall both detect attempts against it as Exp/2668820-A.
CVE-2026-63508 — Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
Every so often, as we read and re-read the available Patch Tuesday information, we see a product name that startles us. So it is with this CVSS Base-10 CVE, for a product that may sound a bit creepy but is simply a newish tool (released in June) for interested parties to ingest and work with geospatial data. It is in any case already patched at this writing.
Sophos protections
| CVE | Sophos Intercept X/Endpoint IPS |
Sophos XGS Firewall |
| CVE-2026-61348 | Exp/2661348-A | Exp/2661348-A |
| CVE-2026-61358 | Exp/2661358-A | Exp/2661358-A |
| CVE-2026-61359 | Exp/2661359-A | Exp/2661359-A |
| CVE-2026-61929 | Exp/2661929-A | Exp/2661929-A |
| CVE-2026-61930 | Exp/2661930-A | Exp/2661930-A |
| CVE-2026-62688 | Exp/2662688-A | Exp/2662688-A |
| CVE-2026-62698 | Exp/2662698-A | Exp/2662698-A |
| CVE-2026-62713 | Exp/2662713-A | Exp/2662713-A |
| CVE-2026-62888 | Exp/2662888-A | Exp/2662888-A |
| CVE-2026-62893 | sid:2312878 | sid:2312878 |
| CVE-2026-63520 | sid:2312881, sid:2312882 | sid:2312881, sid:2312882 |
| CVE-2026-65665 | sid:2312887 | sid:2312887 |
| CVE-2026-65775 | Exp/2665775-A | Exp/2665775-A |
| CVE-2026-65788 | Exp/2665788-A | Exp/2665788-A |
| CVE-2026-66804 | Exp/2666804-A | Exp/2666804-A |
| CVE-2026-68820 | Exp/2668820-A | Exp/2668820-A |
As you can every month, if you don’t want to wait for your system to pull down Microsoft’s updates itself, you can download them manually from the Windows Update Catalog website. Run the winver.exe tool to determine which build of Windows you’re running, then download the Cumulative Update package for your specific system’s architecture and build number.
Appendix: PatchTuesday_August2026
Once again we are dropping the mile-long appendices and present to you all the data you crave in a far more civilized format – an Excel workbook. You’ll find all your favorite appendix data there, in a format that allows readers to pivot and sort to their hearts’ content. The workbook contains multiple sheets:
PT_Summary – key monthly metrics in a single-screen format
PT_PriSevImp – best for sorting by impact, Microsoft-assigned severity / CVSS, impact, and prospects for exploitability
PT_ByProduct – a more granular breakdown focusing on product families; helpful when dealing with CVEs with multi-family applicability
PT_Windows – a chart showing which versions of Windows are affected by each patched CVE
PT_Protections – a list of all Sophos-issued protections applicable to this month’s patches; replicates the chart in the blog post for easy reference
PT_Advisories – not this month! No advisories, no tab
PT_CWE – a breakdown of which vulnerabilities were most often discovered in the products patched in August
