Published Tuesday, August 11, 2026 at 04:30 PM PT

BLUF: Microsoft released August 2026 Patch Tuesday addressing 398–421 vulnerabilities, including 42 critical issues and at least one actively exploited zero-day (use-after-free in afd.sys). Organizations must prioritize critical patches immediately, especially for Windows internet-facing systems.
DETAILS
- Vulnerability count discrepancy: Tenable reports 398 total CVEs (42 Critical, 355 Important); SecurityWeek reports 421 CVEs. Severity distribution and exact count require Microsoft’s official bulletin—both sources are current.
- Active zero-day confirmed: afd.sys use-after-free vulnerability is under active exploitation in the wild (per SecurityWeek). This is not theoretical risk.
- Affected scope: Windows operating systems and .NET components identified in patch notes. Additional affected products likely (context truncated).
- CVE-2026-68820: Referenced as representative CVE for this release; severity level not specified in available material.
- Release date: August 2026 Patch Tuesday (second Tuesday of month, confirmed via Tenable and SecurityWeek reporting).
IMPACT
Affected parties: All organizations running Microsoft Windows (client and server) and .NET Framework/Core deployments. Consumer users also at risk.
Scope: 42 critical vulnerabilities at CVSS 9.0+ represent immediate remote-code-execution or privilege-escalation risk. Active exploitation of afd.sys zero-day elevates urgency: threat actors are weaponizing at least one vulnerability in real time.
Risk window: Systems unpatched within 48–72 hours face elevated compromise probability, especially if Internet-exposed (RDP, SMB, web services).
RECOMMENDED ACTIONS
- Immediate: Deploy critical patches (CVSS ≥9.0) to internet-facing Windows systems within 24 hours. Prioritize servers and workstations with egress to untrusted networks.
- Urgent: Test and deploy afd.sys patch across all affected Windows versions as emergency priority due to active exploitation.
- Short-term: Implement compensating controls for systems unable to patch immediately—disable unnecessary network services, restrict RDP/SMB access, deploy host-based IDS/EDR.
- Monitoring: Search logs and endpoint telemetry for afd.sys exploitation attempts (driver crashes, unexpected privilege elevation, network reconnections post-crash).
SOURCES
- Tenable Blog: Microsoft’s August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
- SecurityWeek: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
- Microsoft Official Patch Tuesday Release (August 2026)
Recent high-severity events at publish time:

