Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-Days

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Microsoft has released its August 2026 Patch Tuesday security updates, addressing a massive 394 vulnerabilities across Windows, Microsoft Office, SharePoint Server, Azure services, .NET, PowerShell, Visual Studio Code, and other enterprise products.

The security release, published on August 11, 2026, also includes fixes for three zero-day vulnerabilities, making prompt patching a critical priority for organizations and individual users.

CVE Affected component Impact Severity Publicly disclosed Exploited in the wild
CVE-2026-72971 Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Important Yes No
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Important Yes No
CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Important No Yes

CVE-2026-72971 affects the unionfs.sys driver used by Windows Container Isolation. Microsoft classifies it as a tampering vulnerability, meaning a successful attack could undermine the integrity of affected container-related files or system behavior. It had already been publicly disclosed when the August update was released, so organizations using Windows container workloads should prioritize patching affected hosts.

CVE-2026-62832 is a publicly disclosed elevation-of-privilege vulnerability in the Windows User Profile Service. Elevation-of-privilege flaws are commonly valuable in attack chains because they can allow an attacker who already has a foothold on an endpoint to obtain broader system-level permissions. While the supplied advisory data does not mark this CVE as exploited, public disclosure raises the likelihood of proof-of-concept development and follow-on exploitation attempts.

CVE-2026-68820 is the most urgent of the three because Microsoft flags it as exploited in the wild. The vulnerability affects the Windows Ancillary Function Driver for WinSock and can enable elevation of privilege on an affected device. Organizations should treat it as an immediate patching priority, investigate suspicious local privilege-escalation activity, and review endpoint telemetry for abnormal process execution or changes in privileged account behavior.

The scale of this month’s Microsoft Patch Tuesday update creates a substantial workload for IT and security teams. Although not every vulnerability will affect every environment, the wide product coverage means enterprises should quickly identify exposed Windows servers, endpoints, cloud workloads, developer systems, and collaboration platforms.

Vulnerability impact Vulnerabilities patched
Elevation of Privilege 150
Remote Code Execution 132
Information Disclosure 66
Spoofing 21
Denial of Service 12
Security Feature Bypass 9
Tampering 4
Total 394

Microsoft has marked the listed vulnerabilities as requiring customer action, reinforcing the importance of applying the available security updates rather than relying solely on compensating controls.

Among the issues requiring attention is CVE-2026-72971, an Important-rated tampering vulnerability in the Windows Container Isolation File System Filter Driver, known as unionfs.sys. Container environments are increasingly used to run modern applications and workloads, making isolation boundaries a significant security concern.

A tampering flaw in a component responsible for containerized file-system behavior could potentially weaken the integrity protections organizations expect when separating workloads. Security administrators running Windows container environments should prioritize assessment and deployment of Microsoft’s update.

Another high-priority flaw is CVE-2026-71331, a Critical remote code execution vulnerability affecting the Microsoft Azure Attestation service and Device Health Attestation Service.

Remote code execution bugs are among the most serious vulnerability classes because successful exploitation may enable an attacker to run malicious code in the context of an affected service.

Device Health Attestation plays an important role in evaluating device security posture, particularly in enterprise environments that use conditional-access controls and endpoint trust signals. Organizations using DHA-related services should validate their exposure and implement the applicable patches without delay.

Microsoft’s August security release also includes several vulnerabilities affecting Microsoft SharePoint Server. These include CVE-2026-70355, CVE-2026-70326, and CVE-2026-70324, which are elevation-of-privilege flaws, as well as CVE-2026-70321, an Important remote code execution vulnerability.

SharePoint remains a valuable target for attackers because it often stores internal documents, business workflows, credentials, and collaboration data.

A successful SharePoint compromise can provide adversaries with a path to sensitive information and further movement inside a corporate network. Administrators should patch internet-facing SharePoint servers first, review access logs for unusual activity, and ensure administrative interfaces are not unnecessarily exposed.

The update also fixes CVE-2026-70354, an Important .NET remote code execution vulnerability, alongside CVE-2026-70337, an Important remote code execution issue in Microsoft PowerShell Core. PowerShell has long been used by administrators for legitimate automation but is also frequently abused by threat actors for reconnaissance, payload execution, and post-exploitation activity.

Microsoft additionally addressed CVE-2026-70338, a PowerShell security feature bypass vulnerability. Defenders should patch affected PowerShell installations and continue monitoring for suspicious encoded commands, unusual child processes, remote execution activity, and attempts to disable endpoint security protections.

Developer environments are also in scope. CVE-2026-70336 affects Visual Studio Code and could allow remote code execution, while CVE-2026-70335 impacts GitHub Copilot and Visual Studio Code through an elevation-of-privilege vulnerability.

Developers should not overlook these updates, especially where workstations have access to production cloud environments, source-code repositories, signing certificates, or deployment pipelines. Compromise of a developer endpoint can become a software supply-chain risk if attackers obtain repository tokens, modify source code, or steal credentials used in CI/CD systems.

Windows infrastructure teams should also review CVE-2026-70330, an elevation-of-privilege vulnerability in Windows DNS, and CVE-2026-70348, a denial-of-service flaw in Windows Management Services.

Microsoft fixed four separate Windows Installer elevation-of-privilege vulnerabilities—CVE-2026-70344 through CVE-2026-70347—which could be relevant to attackers seeking to turn limited access on a system into higher privileges. CVE-2026-70340, affecting Azure CycleCloud, should be evaluated by organizations operating high-performance computing and cloud-cluster workloads.

Office users are covered by a broad collection of Important-rated bugs in Outlook, Excel, Word, PowerPoint, and Microsoft Office. CVE-2026-70329 is a remote code execution vulnerability in Microsoft Outlook, while Excel, Word, PowerPoint, and Office patches address multiple information-disclosure issues.

Even when a vulnerability is not rated Critical, Office flaws can become highly effective in phishing campaigns that use malicious email attachments, shared documents, or deceptive collaboration content.

Organizations should prioritize the three zero-day fixes and Critical vulnerabilities, followed by internet-facing SharePoint, Azure, Windows infrastructure, developer tools, and Office deployments.

Security teams should test patches through their normal change-management process, but should avoid unnecessary delays where systems are exposed or business-critical.

[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now