August 2026 Patch Tuesday: The Vulnerabilities Worth Losing Sleep Over
Microsoft's August 2026 security update addressed 421 vulnerabilities, 62 of them rated critical - 40 of those critical flaws are remote code execution (RCE) bugs. Most patches are routine; a handful are not, and those are the ones worth prioritising this cycle.
What to patch first
- A missing-authorisation flaw in Microsoft Teams scored a full 10.0 on CVSS, allowing unauthenticated network attackers to elevate privileges with no user interaction required.
- CVE-2026-68820, affecting the WinSock AFD driver, has confirmed active exploitation in the wild - treat this as an emergency patch, not a routine one.
- CVE-2026-62832, in the User Profile Service, is publicly known, meaning working exploit details are already circulating, which typically shortens the window before broad exploitation follows.
- CVE-2026-62815, a use-after-free flaw in Microsoft QUIC, scores 9.8 and allows unauthenticated remote code execution with low attack complexity - a serious risk for any internet-facing service using QUIC.
- Windows DNS Server picked up four critical RCE fixes this cycle (CVE-2026-62878, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789), which matters disproportionately for organisations running internal DNS infrastructure on Windows.
What this means for your patch cycle
With 62 critical vulnerabilities landing in a single update, blanket "patch everything within 30 days" policies are too slow for the items above. Triage by exploitability first: confirmed active exploitation and publicly known details should move to the front of the queue regardless of CVSS score, ahead of critical-but-unexploited flaws.
If your organisation runs a regular vulnerability assessment programme, this is exactly the kind of month it exists for - confirming which of these CVEs actually apply to your environment, and which internet-facing assets are exposed, faster than a monthly or quarterly scan cycle alone would surface.
Sources
Have a security question of your own?
Talk to a Security Expert →