www.malwarebytes.com 8/12/2026, 2:11:13 PM · external

MS Patch Tuesday patches 421 flaws, Lazarus zero day exploited

MS Patch Tuesday patches 421 flaws, Lazarus zero day exploited
Developing story vulnerability 1 article tracked
Lazarus exploits Windows zero-day (CVE-2026-62832) patched in August 2026
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CISA KEV Not in KEV
Patch Patch Available
Threat Actor

THE August 2026 Patch Tuesday from Microsoft addresses 421 vulnerabilities, including three critical zero-days and 62 rated as critical. Notably, a flaw exploited by the Lazarus group allows SYSTEM privileges. Key updates include a public Windows privilege escalation flaw, an unauthenticated SharePoint remote code execution (RCE), and a potentially wormable Windows DNS Server flaw. Users are advised to promptly apply updates via Windows Update for protection.

Key vulnerabilities include CVE-2026-62893, an unauthenticated RCE flaw, and CVE-2026-62832, concerning elevation of privilege in the User Profile Service, among 48 RCE fixes for Office applications.

View Primary Source Via www.malwarebytes.com

Article by CyberSIXT