What This August Microsoft Patch Tuesday Is Really About
Microsoft Patch Tuesday August is the monthly release of cumulative security updates that fix vulnerabilities across Windows, Office, Exchange, Azure, and other products, and this cycle stands out because it addresses more than 400 flaws, including an actively exploited Windows zero-day that lets attackers escalate privileges to SYSTEM without user interaction. Microsoft’s latest Patch Tuesday ships fixes for over 400 vulnerabilities, with the company itself counting 421 bugs that span Windows 11 (25H2/24H2, 23H2) and Windows 10, plus key enterprise services like Exchange and SharePoint. Treating this as routine maintenance is a mistake. The sheer volume of flaws is worrying, but the real story is risk: one of these bugs is already being used in real attacks, and several others allow remote code execution without authentication.

The Windows zero-day CVE-2026-68820: Why this one matters most
The headline issue in the August release is CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock (AFD.sys) that lets a low-privileged local attacker elevate privileges to SYSTEM. In plain terms, once an attacker has any foothold on a Windows 10 or Windows 11 system, this bug can hand them complete control without the user doing anything. A locally authenticated attacker can run a specially crafted application to trigger a race condition, and, as Microsoft notes, “user interaction is not required.” This is not theoretical. Researchers report that CVE-2026-68820 has been exploited in the wild to deploy a kernel-mode rootkit in the Operation Dream Job campaign, linked to North Korean attackers. Even though Microsoft labels it “Important” rather than “Critical,” exploitation has been detected in real environments, so this is exactly the kind of zero-day that defenders must patch ahead of everything else.

Beyond the zero-day: other critical security patches you cannot ignore
Focusing only on the Windows zero-day exploit CVE-2026-68820 would be a mistake; this Microsoft Patch Tuesday August release is stacked with other high-impact flaws. Microsoft highlights a critical Microsoft QUIC vulnerability, CVE-2026-62815, where an unauthenticated attacker can send a specially crafted packet to an affected service and, if successful, execute code on the target system with no user interaction at all. Another danger is CVE-2026-62878, a stack-based buffer overflow in Windows DNS that can be easily, reliably and remotely exploited by unauthenticated attackers, again opening the door to remote code execution. On the application side, CVE-2026-63520 in SharePoint can be combined with a previously patched bug (CVE-2026-55040) to achieve unauthenticated remote code execution on vulnerable servers. These are precisely the kinds of critical security patches that attackers automate into their scan-and-exploit tooling long before many organisations finish “testing.”
Who is affected: from home Windows PCs to Exchange and containers
If you run supported versions of Windows 11 (25H2/24H2, 23H2) or Windows 10, this update is aimed squarely at you; Microsoft’s August release covers 421 vulnerabilities across Windows and related products such as Office, Exchange, Azure and SharePoint. The Windows zero-day CVE-2026-68820 hits the core networking driver AFD.sys, so any affected desktop or laptop becomes a stepping stone for attackers once they gain local access. Server and cloud administrators are also in the blast radius. Exchange Server security updates arrive as part of this cycle, while SharePoint and Windows DNS receive fixes for remotely exploitable flaws. There is even a bug specific to Windows 11 on ARM64, CVE-2026-72971, in the Windows Container Isolation FS Filter Driver , which may let authenticated attackers tamper with the system. In short, both endpoint and server estates are in play, and ignoring either side leaves a gap.
What to do now: prioritized patching steps for Windows and Exchange
Microsoft Patch Tuesday updates are mandatory and should automatically download on supported PCs, but relying on “automatic” is not a security strategy. For Windows 11, go to Settings → Windows Update, click “Check for updates,” install the August cumulative update, and reboot when prompted; Windows 10 users should head to Settings → Update & Security → Windows Update. If you depend on the Extended Security Updates program for Windows 10, make sure your ESU enrollment is current so you continue receiving these patches. On the server side, prioritise installing Exchange Server security updates and patching any exposed SharePoint and DNS servers, especially where they face the internet. My opinionated order of operations is simple: first, patch all internet-facing servers; second, update endpoints vulnerable to CVE-2026-68820; third, complete the rest of the August stack. Exploitation has already been detected in the wild, so delaying this cycle is equivalent to leaving your front door unlocked.




