Home Technology Microsoft August Patch Tuesday Fixes About 400 Bugs

Microsoft August Patch Tuesday Fixes About 400 Bugs

9
0


Microsoft released patches for over 400 CVEs this Patch Tuesday, including one actively exploited zero-day and several critical remote code execution flaws that require no user interaction.

Security teams face the challenge of triaging this overwhelming volume while managing the risk of patching itself.

The zero-day that matters most

CVE-2026-68820 is the vulnerability demanding immediate attention. This use-after-free flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) allows a locally authenticated attacker with low privileges to gain SYSTEM-level access.

“The primary threat is local privilege escalation,” Mike Walters, President and Co-Founder of Action1, told TechRepublic. “An attacker who already has low-privileged access could exploit the vulnerability to gain SYSTEM privileges, potentially obtaining extensive control over the affected Windows system.”

Check Point Research reported that North Korean attackers have been using the vulnerability in a new wave of the Operation Dream Job campaign to deploy kernel-mode rootkits.

This marks the fourth afd.sys zero-day exploited in the wild since 2022, with previous iterations linked to Lazarus Group activity.

A second vulnerability, CVE-2026-62832, was publicly disclosed before a patch was available.

This Windows User Profile Service elevation-of-privilege flaw allows an authenticated attacker to load another user’s registry hive and gain administrator privileges. While not yet exploited in the wild, Microsoft assesses exploitation as “More Likely,” making it a high priority for deployment.

The four 9.8s: No click, no credentials required

Four critical vulnerabilities carry CVSS scores of 9.8 and require no authentication or user interaction:

  • CVE-2026-62878 (Windows DNS Server): A stack-based buffer overflow that the Zero Day Initiative describes as technically wormable
  • CVE-2026-62893 (Windows Deployment Services TFTP server)
  • CVE-2026-62815 (Microsoft QUIC)
  • CVE-2026-59124 (Microsoft HPC Pack) — rated Important rather than Critical since HPC Pack isn’t installed by default

“An unauthenticated attacker can send a specially crafted packet to an affected service over the network and potentially execute code on the target system,” said Alex Vovk, CEO and Co-Founder of Action1, describing the DNS Server flaw.

A SharePoint chain completed

August closes the second half of a two-part SharePoint fix that began in July. Rapid7 Labs reported an exploit chain combining an authentication bypass (CVE-2026-55040, patched in July) with a code execution vulnerability (CVE-2026-63520, patched this month) to achieve unauthenticated remote code execution against on-premises SharePoint servers.

If you applied July’s update, that attack route is already blocked. The August fix now closes the RCE component as well.

The ‘ShieldBreak’ exploit drop

Just hours after Microsoft published its fixes, security researcher “Nightmare Eclipse” published details and proof-of-concept code for a brand-new Windows zero-day dubbed “ShieldBreak.”

The flaw bypasses Microsoft’s July patch for CVE-2026-50656 (RoguePlanet) and targets Windows Defender, allowing an attacker to elevate local permissions to SYSTEM privileges on Windows 10, Windows 11, and Windows Server 2025.

Security expert Kevin Beaumont confirmed the exploit works on fully patched systems.

Nightmare Eclipse has now released 10 zero-days targeting Microsoft since April, driven by an ongoing dispute over the tech giant’s handling of vulnerability reports and previous threats of legal action.

A Microsoft spokesperson told TechCrunch the company is “aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims.”

Strategic defender prioritization

The sheer volume of monthly security updates presents a structural challenge for enterprise IT departments, making blanket deployments nearly impossible without risking operational disruption.

Amol Sarwate, Head of Security Research and REDLab at Cohesity, emphasized the operational risk of combining flaws.

“Used together, the two vulnerabilities could turn an initial foothold — such as a successful phishing attack — into a complete system compromise. That makes this pair the clear priority for defenders this month,” Sarwate told TechRepublic.

The simultaneous arrival of hundreds of official fixes alongside unpatched, publicly disclosed zero-days leaves system administrators facing an impossible balancing act. Rushing patch deployments without testing risks crashing critical production environments, yet delaying leaves endpoints exposed to active exploits like CVE-2026-68820.

Furthermore, because ShieldBreak targets Windows Defender directly, standard endpoint protection tools may fail to stop local privilege escalation until Microsoft releases an official fix.

Organizations must rely on alternative threat-hunting queries and strictly limit local user privileges to slow down potential attackers already inside the network.

Also read: Our Windows 11 security cheat sheet explains how Microsoft Defender, BitLocker, passkeys, and other built-in protections work together.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here