3 min read

Microsoft patches 400 flaws and three zero-days

Microsoft’s August 2026 Patch Tuesday fixes 400 flaws, including an exploited Windows zero-day used by Lazarus to deploy a rootkit.

Source: Bleepingcomputer

Microsoft’s August 2026 Patch Tuesday fixes 400 vulnerabilities, including three zero-days: one actively exploited and two that had already been publicly disclosed. The update covers 42 critical flaws, 37 of them remote-code-execution vulnerabilities and five involving privilege escalation, according to BleepingComputer.

The total is lower than July’s 570 fixes, but remains unusually high. Microsoft has attributed the recent rise in security updates to an AI-powered vulnerability discovery system now being used across its software products.

The actively exploited flaw, CVE-2026-68820, is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock. An authenticated local attacker can exploit it to obtain SYSTEM privileges without user interaction. Check Point said North Korean Lazarus operators used the flaw to deploy a new version of the FudModule kernel-mode rootkit. Microsoft has not disclosed how the attacks were carried out.

Recommended reading

Zoom flaw exposed devices across every major platform

The two publicly disclosed privilege-escalation flaws affect Windows services:

  • A Windows User Profile service flaw allows an attacker with credentials for another local account to load and modify an administrator’s registry hive. Its behavior matches the “LegacyHive” vulnerability disclosed by researcher Nightmare Eclipse, although Microsoft credited the issue to an anonymous researcher.
  • A flaw in the Windows Container Isolation file-system filter driver, unionfs.sys, also lets an authenticated local attacker tamper with files and potentially gain administrator privileges. Microsoft credited its discovery to yhw and txz.

BleepingComputer’s full Patch Tuesday report lists fixes across Windows, Microsoft Office, Exchange Server, Azure services, Entra, .NET, and other products. The release also includes vulnerabilities in products such as GitHub Copilot and Visual Studio Code, Microsoft 365 Admin Center, and Azure Kubernetes Service.

Windows 11 updates add security and usability changes

Microsoft is distributing the security fixes through mandatory Windows 11 cumulative updates. BleepingComputer’s Windows 11 report identifies the packages as KB5121003 for Windows 11 versions 25H2 and 24H2, and KB5120240 for version 23H2. Its article text contains a conflicting reference to KB512103, so users should verify the package number in Windows Update or the Microsoft Update Catalog before installing manually.

The Windows 11 release is based on the 24H2 update and brings the same changes to 25H2, with no version-exclusive features. Notable changes include:

  • File Explorer now displays file sizes in appropriate units such as KB, MB, and GB, supports middle-click folder opening in new tabs from the Address Bar and Home page, and improves thumbnail rendering.
  • Windows Search handles typos and partial app names more effectively and gives Settings results higher relevance.
  • Voice Access adds Voice Isolation, background-noise-only filtering, and Korean language support.
  • Precision touchpads gain adjustable scroll and zoom speed plus accelerated scrolling.
  • Windows Hello Enhanced Sign-in Security now supports supported external fingerprint readers, including on desktops and Copilot+ PCs.
  • Users can remove the Image Generation AI component from supported Copilot+ PCs where it is installed.
  • Power settings now apply more reliably across power plans, and the energy-saver activation threshold can be configured again.

Microsoft said it was not aware of new issues with the August 2026 release at publication time. Windows users can install the update through Start > Settings > Windows Update > Check for updates, or download it manually from the Microsoft Update Catalog.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

/ Keep reading