ON August 11, Microsoft addressed a total of 400 vulnerabilities during its Patch Tuesday, including a significant zero-day issue (CVE-2026-68820) that is actively exploited. This vulnerability, affecting the Windows Ancillary Function Driver, may allow attackers to gain extensive control over a system. Other notable zero-days disclosed include CVE-2026-62832 and CVE-2026-72971, which involve privilege escalation and local tampering, respectively.
The majority of the vulnerabilities fixed in this round are categorized as elevation of privilege and remote code execution flaws, with 37 labeled as critical.