Microsoft’s August 2026 Patch Tuesday Fixes 394 Vulnerabilities, Including 3 Zero-Days

Microsoft has released its August 2026 Patch Tuesday updates, addressing a substantial 394 vulnerabilities across various products, including Windows, Microsoft Office, SharePoint Server, Azure services, .NET, PowerShell, and Visual Studio Code. This comprehensive update also includes fixes for three zero-day vulnerabilities, underscoring the importance of prompt patching for both organizations and individual users.

Zero-Day Vulnerabilities Addressed

The three zero-day vulnerabilities patched in this release are:

  • CVE-2026-72971: A tampering vulnerability in the Windows Container Isolation FS Filter Driver (`unionfs.sys`). Publicly disclosed prior to the update, this flaw could compromise the integrity of container-related files or system behavior. Organizations utilizing Windows container workloads should prioritize patching affected hosts.
  • CVE-2026-62832: An elevation-of-privilege vulnerability in the Windows User Profile Service. Although not marked as exploited, its public disclosure increases the risk of exploitation. Attackers could leverage this flaw to gain higher system-level permissions.
  • CVE-2026-68820: An elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock. This flaw has been exploited in the wild, making it imperative for organizations to apply the patch immediately and monitor for unusual privileged account activities.

Breakdown of Vulnerabilities

The 394 vulnerabilities addressed in this update are categorized as follows:

  • Elevation of Privilege: 150
  • Remote Code Execution: 132
  • Information Disclosure: 66
  • Spoofing: 21
  • Denial of Service: 12
  • Security Feature Bypass: 9
  • Tampering: 4

Microsoft has emphasized the necessity of customer action to apply these updates, highlighting that relying solely on compensating controls is insufficient.

Notable Vulnerabilities

Among the critical vulnerabilities addressed is CVE-2026-71331, a remote code execution flaw affecting the Microsoft Azure Attestation service and Device Health Attestation Service. Successful exploitation could allow attackers to execute malicious code within the context of the affected service, posing significant risks to enterprise environments that rely on these services for device security posture evaluations.

Given the extensive scope of this update, IT and security teams face a considerable workload. It’s crucial for enterprises to swiftly identify and patch exposed systems, including Windows servers, endpoints, cloud workloads, developer systems, and collaboration platforms.

Regular and timely application of security updates is essential to maintain system integrity and protect against potential exploits. Organizations should establish robust patch management processes to address vulnerabilities promptly and mitigate associated risks.