MICROSOFT'S August 2026 Patch Tuesday update addresses 398 CVEs, including a zero-day vulnerability (CVE-2026-68820) and a wormable flaw (CVE-2026-62878) in Windows DNS Server. CVE-2026-68820 is a critical use-after-free bug in the WinSock driver that can allow code execution with SYSTEM-level privileges. CVE-2026-62878 allows remote, unauthenticated attackers to execute code with elevated privileges, necessitating immediate patching.
Other critical vulnerabilities relate to Windows Deployment Services and Microsoft's QUIC protocol. The update includes fixes for elevation of privileges vulnerabilities on Exchange servers and various other components.