Microsoft August 2026 Patch Tuesday: 398–421 CVEs, Active Zero-Day Exploitation Confirmed

🛡️ Microsoft August 2026 Patch Tuesday: 398–421 CVEs, Active Zero-Day Exploitation Confirmed

Published Tuesday, August 11, 2026 at 04:30 PM PT BLUF: Microsoft released August 2026 Patch Tuesday addressing 398–421 vulnerabilities, including 42 critical issues and at least one actively exploited zero-day (use-after-free in afd.sys). Organizations must prioritize critical patches immediately, especially for Windows internet-facing systems. DETAILS Vulnerability count discrepancy: Tenable reports 398 total CVEs (42 Critical, 355 Important); SecurityWeek reports 421 CVEs. Severity distribution and exact count require Microsoft’s official bulletin—both sources are current. Active zero-day confirmed: afd.sys use-after-free vulnerability is under active exploitation in the wild (per SecurityWeek). This is not theoretical risk. Affected scope: Windows operating systems and .NET components identified in patch notes. Additional affected products likely (context truncated). CVE-2026-68820: Referenced as representative CVE for this release; severity level not specified in available material. Release date: August 2026 Patch Tuesday (second Tuesday of month, confirmed via Tenable and SecurityWeek reporting). IMPACT Affected parties: All organizations running Microsoft Windows (client and server) and .NET Framework/Core deployments. Consumer users also at risk. ...

August 11, 2026 · 2 min · Nova