Microsoft’s August 2026 Patch Tuesday Fixes 400+ Vulnerabilities, Including Three Zero-Days

Microsoft has launched its August 2026 Patch Tuesday safety updates, addressing over 400 vulnerabilities throughout Home windows and different supported merchandise, together with three zero-day flaws that have been exploited or publicly disclosed earlier than fixes grew to become obtainable.

Essentially the most pressing vulnerability is an elevation-of-privilege flaw within the Home windows Ancillary Operate Driver for WinSock, tracked as CVE-2026-68820. Microsoft confirmed that attackers had exploited the vulnerability within the wild, whereas Test Level attributed the noticed assaults to the North Korean state-sponsored group extensively generally known as Lazarus.

In response to Test Level, Lazarus used the vulnerability to put in a brand new model of FudModule, a complicated kernel-mode rootkit beforehand related to North Korean espionage operations. The exploitation fashioned a part of a marketing campaign by which targets have been approached with fraudulent employment alternatives earlier than malicious software program was delivered to their programs.

The August launch additionally fixes two vulnerabilities that have been publicly recognized earlier than patches grew to become obtainable: a Home windows Person Profile Service flaw matching the beforehand disclosed “LegacyHive” method and a tampering vulnerability within the Home windows Container Isolation file-system filter driver.

Though the entire is decrease than the unusually giant July Patch Tuesday release, which varied counting methodologies positioned 600+ vulnerabilities, August stays one among Microsoft’s largest month-to-month safety updates. The persevering with quantity underlines the rising operational stress on enterprise patch-management groups, notably as Microsoft expands its use of synthetic intelligence to determine weaknesses throughout Home windows and different complicated codebases.

Extra Than 100 Distant-Code-Execution Vulnerabilities

Microsoft’s August safety launch contains 42 vulnerabilities labeled as Essential. Of these, 37 may result in distant code execution, whereas 5 may enable an attacker to raise privileges.

The roughly 400 vulnerabilities embody :

  • 176 elevation-of-privilege flaws
  • 110 remote-code-execution vulnerabilities
  • 86 information-disclosure points
  • 21 spoofing vulnerabilities
  • 12 denial-of-service flaws
  • 11 security-feature bypasses
  • 4 Tampering flaws

These class figures mustn’t essentially be handled as a easy mathematical complete. Patch Tuesday counts can differ relying on whether or not researchers embody vulnerabilities printed earlier within the month, browser points inherited from Chromium, cloud-service fixes and vulnerabilities that fall into a couple of technical class.

The 400-flaw estimate covers the vulnerabilities Microsoft launched as a part of the August 11 Patch Tuesday cycle. It doesn’t embody sure flaws in providers and merchandise akin to Microsoft Azure, Microsoft Entra, Microsoft Groups, Microsoft Workplace, Energy Apps and Microsoft’s Mariner Linux distribution that have been corrected or disclosed individually earlier in August.

This distinction has change into more and more vital as Microsoft’s portfolio has expanded past conventional Home windows and Workplace software program. Many cloud vulnerabilities are fastened routinely by Microsoft and require no direct buyer motion, whereas vulnerabilities in self-hosted merchandise and Home windows endpoints typically rely on organisations testing and deploying the related updates.

For safety groups, the headline quantity is consequently much less vital than the placement, exploitability and publicity of the affected elements. An actively exploited privilege-escalation flaw on worker workstations, for instance, could signify a extra instant hazard than a higher-scoring remote-code-execution flaw affecting a element that’s disabled or remoted in a specific setting.

Article content

Lazarus Exploited Home windows Kernel Flaw

The very best-priority vulnerability within the August launch is CVE-2026-68820, an elevation-of-privilege vulnerability within the Home windows Ancillary Operate Driver for WinSock, generally represented by the afd.sys kernel driver.

The driving force offers kernel-level assist for Home windows networking operations and acts as an interface between user-mode Winsock purposes and the underlying Home windows networking stack. As a result of it operates in kernel mode, a profitable memory-corruption exploit can enable an attacker to cross a vital safety boundary and acquire the very best degree of privileges on a Home windows machine.

Microsoft described the vulnerability as a use-after-free situation. These flaws happen when software program continues to reference a area of reminiscence after it has been launched, probably permitting an attacker to control the reused reminiscence and alter program execution.

Exploitation requires the attacker to be regionally authenticated and capable of run a specifically constructed utility. The appliance triggers a race situation within the susceptible driver, after which profitable exploitation can grant SYSTEM privileges. No consumer interplay is required as soon as the attacker is able to execute the trojan horse.

The native nature of the vulnerability doesn’t make it a low-priority challenge. Privilege-escalation bugs are generally used because the second stage of an intrusion. An attacker could initially receive restricted entry by way of phishing, malicious paperwork, stolen credentials, browser exploitation or compromised software program. A kernel vulnerability can then be used to flee the restrictions of the compromised account, disable safety controls, entry protected credentials and set up sturdy persistence.

Microsoft credited Test Level researchers Moshe Marelus and David Driker with discovering and reporting CVE-2026-68820.

Faux Job Supply Led to Zero-Day Deployment

In its investigation, Test Level linked CVE-2026-68820 to a Lazarus marketing campaign constructed round fraudulent employment alternatives. The usage of pretend recruitment approaches is a well-established function of North Korean cyber operations, notably campaigns focusing on software program builders, cryptocurrency corporations, defence organisations and know-how staff with entry to worthwhile programs.

In response to Check Point’s technical investigation, the attackers exploited CVE-2026-68820 to deploy a newly noticed model of FudModule, a kernel-mode rootkit linked to Lazarus.

The assault chain is critical as a result of it combines social engineering with a beforehand unknown kernel vulnerability. The preliminary job-themed contact provides the attackers a route to steer a goal to open a file, run a mission or set up software program. As soon as code is working with atypical consumer privileges, the Home windows flaw offers the escalation wanted to grab deeper management of the endpoint.

FudModule is designed to function at a degree the place it will probably intrude with safety merchandise and conceal malicious exercise. Kernel-mode implants are notably harmful as a result of they run inside some of the trusted layers of the working system. Relying on their capabilities, rootkits working at this degree could manipulate system buildings, cover processes, block telemetry, alter security-tool behaviour or defend different malware elements from removing.

The usage of CVE-2026-68820 due to this fact seems to have served a particular operational function: turning an preliminary, lower-privileged compromise right into a extremely privileged and extra difficult-to-detect intrusion.

Microsoft’s advisory confirms that exploitation was detected however doesn’t present particulars concerning the affected organisations, the size of the marketing campaign or the entire supply chain. The corporate’s restricted disclosure is typical when an investigation stays energetic or when publishing further data may expose victims and defensive strategies.

CVE-2026-68820 ought to obtain instant consideration throughout Home windows workstations, developer programs and different gadgets on which customers can execute downloaded purposes. Organisations in sectors traditionally focused by Lazarus must also examine for proof of compromise fairly than assuming that putting in the patch will take away an present an infection.

A safety replace closes the vulnerability, but it surely doesn’t routinely evict an attacker who exploited the flaw earlier than the replace was put in.

FudModule Provides to Lazarus’ Kernel-Degree Arsenal

Lazarus is an umbrella identify used for a number of North Korean cyber models and operational clusters. The broader ecosystem has been linked to intelligence assortment, damaging assaults, cryptocurrency theft and financially motivated operations supposed to generate income for the North Korean state.

The group’s curiosity in kernel-level capabilities will not be new. Earlier FudModule campaigns have demonstrated a willingness to take advantage of Home windows drivers and different privileged elements to weaken endpoint protections. The deployment of an up to date rootkit by way of a real Home windows zero-day exhibits that these operators proceed to spend money on strategies that present stealth and resilience after preliminary entry.

Faux recruitment campaigns are particularly efficient in opposition to technical professionals as a result of the malicious materials may be disguised as a coding evaluation, software program mission, wage doc or video-interview utility. The sufferer could anticipate to obtain recordsdata or execute code as a part of a authentic hiring course of, lowering the chance that the exercise will initially seem suspicious.

Defenders ought to consequently look past typical electronic mail attachments. Recruitment-themed assaults could start by way of skilled networking providers, messaging platforms or developer communities earlier than transferring to electronic mail or attacker-controlled web sites.

Safety groups ought to look at uncommon baby processes launched by growth instruments, archive utilities, doc readers and messaging purposes. They need to additionally monitor for surprising driver exercise, makes an attempt to tamper with endpoint-security providers and anomalous SYSTEM-level processes showing shortly after a consumer runs recruitment-related materials.

LegacyHive Public Disclosure Addressed

The second zero-day fastened in August is CVE-2026-62832, an elevation-of-privilege vulnerability within the Home windows Person Profile Service.

Microsoft stated the weak spot outcomes from improper hyperlink decision earlier than file entry, a category of vulnerability sometimes called hyperlink following. An attacker with native entry and credentials for one more account can use a specifically constructed utility to trigger the Person Profile Service to load one other consumer’s registry hive.

Profitable exploitation may enable the attacker to entry or modify knowledge belonging to the focused account and in the end receive administrator privileges. The assault doesn’t require interplay from the focused consumer whereas the exploit is working, though some types of the method could rely on subsequent account exercise.

The technical description carefully matches the Home windows vulnerability publicly disclosed in July underneath the identify LegacyHive. Microsoft credited CVE-2026-62832 to an nameless researcher, whereas the general public LegacyHive proof of idea was launched by a researcher utilizing the identify Nightmare Eclipse.

LegacyHive focused the best way the Home windows Person Profile Service handles registry hive recordsdata, symbolic hyperlinks and timing-sensitive file operations. The registry accommodates in depth configuration data for Home windows, put in purposes and particular person consumer accounts. A registry hive akin to UsrClass.dat can comprise utility knowledge, Explorer historical past, shell configuration and different user-specific data.

Evaluation by Cyderes discovered that the publicly demonstrated method used symbolic-link manipulation and an opportunistic file lock to affect profile loading at a exact level within the operation. The proof of idea brought about the service to load a goal consumer’s registry hive right into a namespace accessible to the lower-privileged account.

ThreatLocker’s analysis reported that the unique public demonstration uncovered one other consumer’s registry knowledge and that modifications to the method may probably goal different hive recordsdata. Safety researcher Will Dormann additionally warned that manipulating a privileged consumer’s hive may create a path to executing instructions with administrative rights when that consumer subsequently signed in.

The August patch closes the hole that remained after LegacyHive was publicly demonstrated in opposition to programs carrying the July safety updates.

As a result of working technical data had already been launched, CVE-2026-62832 deserves accelerated therapy regardless that Microsoft had not reported energetic exploitation on the time of publication. Public proof-of-concept code considerably reduces the analysis required for different menace actors to breed or adapt an assault.

Shared workstations, bounce servers, multi-user programs and machines the place directors repeatedly register alongside lower-privileged customers could face better publicity. The vulnerability additionally reinforces the significance of protecting privileged administrative exercise separate from atypical consumer computing.

Container Isolation Driver Vulnerability Additionally Publicly Identified

Microsoft additionally fastened CVE-2026-72971, a publicly disclosed tampering vulnerability within the Home windows Container Isolation file-system filter driver, unionfs.sys.

The driving force is concerned in presenting and managing layered file-system views utilized by Home windows container-isolation options. Microsoft attributed the vulnerability to researchers recognized as yhw and txz.

As with the Person Profile Service flaw, Microsoft described the underlying weak spot as improper hyperlink decision earlier than file entry. This implies an authenticated native attacker could possibly manipulate file-system hyperlinks so {that a} privileged element accesses or adjustments a location apart from the one it supposed to course of.

The unique report seems to repeat some textual content related to CVE-2026-62832, together with references to loading one other consumer’s registry hive and gaining administrator privileges. That description belongs to the Person Profile Service vulnerability and shouldn’t be handled because the definitive exploitation path for the container driver flaw.

The dependable parts of Microsoft’s disclosure are that CVE-2026-72971 impacts unionfs.sys, requires an authorised native attacker and might allow file-system tampering. Microsoft had not publicly described the precise disclosure route, demonstrated assault chain or proof of in-the-wild exploitation when the August updates have been launched.

The dearth of reported exploitation shouldn’t be confused with an absence of threat. Container-isolation mechanisms exist to implement boundaries between purposes, recordsdata and host assets. A weak spot within the supporting file-system layer may change into extra severe if mixed with one other vulnerability that gives code execution inside a restricted setting.

Organisations utilizing Home windows containers or container-based application-isolation applied sciences ought to check and deploy the related updates promptly. They need to additionally assessment host telemetry for suspicious symbolic-link creation, surprising modification of protected recordsdata and strange exercise involving container storage paths.

Patch Tuesday Volumes Proceed to Rise

August’s 400-flaw launch follows an exceptionally giant July replace that addressed roughly 570 vulnerabilities underneath the counting methodology utilized by a number of safety companies. Different organisations reported totally different totals as a result of Microsoft’s Safety Replace Information included further entries, whereas some analyses excluded Chromium, cloud-only points or vulnerabilities printed outdoors the primary launch window.

The disagreement illustrates why uncooked Patch Tuesday totals require context. Completely different studies could all be internally correct whereas measuring totally different units of vulnerabilities.

What is evident is that Microsoft safety releases have gotten bigger. The corporate warned in Could that prospects ought to anticipate the development to proceed as vulnerability reporting, automation and AI-assisted code evaluation broaden.

Microsoft has developed a multi-model vulnerability-discovery platform generally known as MDASH, which coordinates greater than 100 specialised AI brokers to analyse software program and validate potential weaknesses. The corporate stated the system discovered all 21 intentionally launched vulnerabilities in a personal check driver with out producing a false constructive throughout that check. It additionally reported sturdy outcomes in opposition to historic Microsoft vulnerabilities and the CyberGym safety benchmark.

Microsoft stated MDASH had already contributed to the invention of 16 vulnerabilities launched in Could, together with flaws within the Home windows networking and authentication stack. The corporate later expanded its use throughout Home windows, Azure, Hyper-V, Energetic Listing, identification providers and different security-sensitive elements. Microsoft’s research means that AI-assisted evaluation is permitting engineers to look at code paths at a depth and scale that will be tough to realize manually.

In a separate Microsoft Security Response Center statement, the corporate stated the rise was not the results of a lowered threshold for issuing safety fixes. As a substitute, Microsoft attributed the expansion to extra researcher participation, improved automation, expanded validation and better use of AI by each inner groups and exterior researchers.

Bigger Patch Tuesday releases don’t essentially imply that Microsoft software program has all of a sudden change into much less safe. They might as an alternative mirror a better means to find and remediate latent vulnerabilities. Nevertheless, the consequence for patrons is similar: extra updates should be assessed, examined and deployed inside more and more compressed timeframes.

Enterprises Ought to Prioritise Exploitation, Publicity and Affect

Organisations ought to place CVE-2026-68820 on the prime of the August deployment queue as a result of exploitation has already been confirmed. Excessive-risk worker teams, together with builders, cryptocurrency personnel, defence contractors, researchers and executives, warrant explicit consideration due to Lazarus’ documented use of focused job-offer lures.

Affected gadgets must be patched as rapidly as operationally attainable and reviewed for proof of earlier compromise. Endpoint detection instruments must be checked to make sure that their sensors are working usually and haven’t been disabled or tampered with. The place suspicious exercise is recognized, organisations ought to isolate the machine, protect forensic proof and examine credentials used on the system.

CVE-2026-62832 ought to observe carefully as a result of technical particulars and proof-of-concept materials for LegacyHive have been public since July. Techniques shared by a number of customers or used for privileged administration deserve precedence.

CVE-2026-72971 must be prioritised on Home windows programs supporting containers or application-isolation workloads, notably the place untrusted or lower-trust code can execute on the identical host.

Directors should additionally determine the 42 Essential vulnerabilities related to their environments, particularly the 37 remote-code-execution points. Web-facing providers, area infrastructure, remote-access programs, developer endpoints and machines processing recordsdata from exterior sources ought to obtain heightened scrutiny.

The August launch as soon as once more exhibits that CVSS severity alone will not be an satisfactory patching technique. Essentially the most pressing flaw within the launch is vital not merely due to its technical traits, however as a result of a succesful state-backed group has already integrated it right into a working assault chain.

As Microsoft and impartial researchers use AI to search out vulnerabilities sooner, attackers are having access to more and more succesful instruments for analysing updates and growing exploits. The interval between patch publication and widespread exploitation is due to this fact more likely to contract additional.

For defenders, the central lesson from August Patch Tuesday will not be merely that 400 flaws have been corrected. It’s that a type of flaws had already change into a part of an actual North Korean intrusion operation, two others have been publicly documented, and delayed patching now provides attackers an more and more slender however extremely worthwhile window of alternative.

Article content

Article content

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *