Full Report
42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.This month’s update includes patches for:.NET.NET Core.NET FrameworkAMD ZenActive Directory Certificate Services (AD CS)Application Information ServicesAzure Active DirectoryAzure CycleCloudAzure Monitor AgentAzure Storage ExplorerCapability Access Management Service (camsvc)Desktop Window ManagerDynamics Business CentralGitHub Copilot and Visual Studio CodeMicrosoft Azure Attestation service and Device Health Attestation ServiceMicrosoft COM for WindowsMicrosoft Defender for EndpointMicrosoft Digest AuthenticationMicrosoft Dynamics 365 (on-premises)Microsoft Entra Connect SyncMicrosoft Exchange ServerMicrosoft High Performance Computing (HPC) PackMicrosoft Identity ServicesMicrosoft Local Security Authority Server (lsasrv)Microsoft OfficeMicrosoft Office AccessMicrosoft Office ExcelMicrosoft Office Graphics ComponentMicrosoft Office OutlookMicrosoft Office PowerPointMicrosoft Office SharePointMicrosoft Office WordMicrosoft OneDriveMicrosoft PowerShellMicrosoft PowerShell CoreMicrosoft QUICMicrosoft Remote Registry ServiceMicrosoft Teams MobileMicrosoft Teams for AndroidMicrosoft Windows Codecs LibraryMicrosoft Windows Media FoundationMicrosoft Windows Search ComponentPower BIRPC RuntimeReliable Multicast Transport Driver (RMCAST)Remote Desktop ClientUser-Mode Power Service (UMPS)Virtual Hard Disk (VHD) Miniport DriverVisual Studio CodeVisual Studio Code - Python extensionVisual Studio Code CoPilot Chat ExtensionWindows Accessibility Infrastructure (ATBroker.exe)Windows Active DirectoryWindows Ancillary Function Driver for WinSockWindows AutopilotWindows Backup EngineWindows Bind Filter DriverWindows Cloud Files Mini Filter DriverWindows Common Log File System DriverWindows Container Isolation FS Filter Driver (unionfs.sys)Windows Cross Device ServiceWindows DHCP ClientWindows DHCP ServerWindows DNSWindows DWM Core LibraryWindows Defender Firewall ServiceWindows Deployment ServicesWindows Device Association ServiceWindows Display Enhancement ServiceWindows Encrypting File System (EFS)Windows Event Logging ServiceWindows GDIWindows GDI+Windows Graphics KernelWindows HTTP Protocol StackWindows HTTP.sysWindows HelloWindows Hyper-VWindows Imaging ComponentWindows InstallerWindows KerberosWindows KernelWindows Key GuardWindows LDAP - Lightweight Directory Access ProtocolWindows LUAFVWindows License ManagerWindows MIDI Service ModuleWindows Management InstrumentationWindows Management ServicesWindows Message QueuingWindows Modern Device Management (MDM)Windows NTFSWindows Narrator BrailleWindows Network Address Translation (NAT)Windows Network Connection BrokerWindows Network File SystemWindows Package ManagerWindows Program Compatibility Assistant ServiceWindows Projected File SystemWindows Push NotificationsWindows RPC APIWindows Remote Access APIWindows Remote Access Connection ManagerWindows Remote Desktop ServicesWindows Remote HelpWindows Remote Help DefenseWindows Routing and Remote Access Service (RRAS)Windows SMB ClientWindows SMB ServerWindows SchannelWindows Secure Socket Tunneling Protocol (SSTP)Windows Sensor Data ServiceWindows ShellWindows StorageWindows Storage Port DriverWindows TCP/IPWindows Telephony ServiceWindows USB DriverWindows Universal Disk Format File System Driver (UDFS)Windows User Profile ServiceWindows Win32KWindows Wired AutoConfig ServiceWindows Work Folder ServiceWindows iSCSI Target ServiceWinlogonElevation of Privilege (EoP) vulnerabilities accounted for 40.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 27.1%.ImportantCVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityCVE-2026-68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and was rated as important. A local attacker could exploit this vulnerability to elevate to SYSTEM privileges. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.Two additional EoP vulnerabilities affecting this driver were patched this month. CVE-2026-61348 and CVE-2026-70307 also received CVSSv3 scores of 7.0, however no exploitation has been reported for these flaws. Both were assessed as "Exploitation More Likely" according to Microsoft's Exploitability Index.Prior zero-days in this driver include CVE-2025-32709 in May 2025, CVE-2025-21418 in February 2025, and CVE-2024-38193 in August 2024.ImportantCVE-2026-62832 | Windows User Profile Service Elevation of Privilege VulnerabilityCVE-2026-62832 is an elevation of privilege vulnerability affecting Windows User Profile Service. It received a CVSSv3 score of 7.8 and is rated as important. A local attacker could exploit this vulnerability to gain ADMINISTRATOR privileges. It was publicly disclosed prior to a patch being available and was assessed as “Exploitation More Likely.”Historically, the Windows User Profile Service has received four total CVEs since January 2022. Prior zero-days in this family include CVE-2022-21919 in January 2022 and CVE-2022-26904 in April 2022.ImportantCVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering VulnerabilityCVE-2026-72971 is a tampering vulnerability affecting the Windows Container Isolation FS Filter Driver (unionfs.sys). It received a CVSSv3 score of 5.5 and is rated as important. It was publicly disclosed prior to a patch being available. Successful exploitation would allow a local attacker to perform tampering. Despite being publicly disclosed, Microsoft assesses this vulnerability as “Exploitation Unlikely.”CriticalCVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution VulnerabilityCVE-2026-62893 is a remote code execution vulnerability affecting Windows Deployment Services Trivial File Transfer Protocol (TFTP) Server. It received a CVSSv3 score of 9.8 and is rated as critical. It was assessed as "Exploitation More Likely." Successful exploitation of this flaw could occur when a remote, unauthenticated attacker sends crafted packets to a vulnerable service, resulting in code execution. It was reported to Microsoft by Nikolai Skliarenko of TrendAI Research.CriticalCVE-2026-62823 | Windows DHCP Server Remote Code Execution VulnerabilityCVE-2026-62823 is a remote code execution vulnerability affecting Windows DHCP Server. It received a CVSSv3 score of 8.8 and is rated as critical. It was assessed as "Exploitation More Likely" according to Microsoft's Exploitability Index. Successful exploitation would allow a remote, unauthenticated attacker to execute code over an adjacent network by exploiting a heap-based buffer overflow flaw using a crafted packet.13 additional Windows DHCP server vulnerabilities were patched this month, however these flaws were only rated as important. The flaws include eight information disclosure vulnerabilities with CVSSv3 scores of 6.5 (CVE-2026-62714, CVE-2026-62715, CVE-2026-62716, CVE-2026-62718, CVE-2026-62720, CVE-2026-62742, CVE-2026-62745 and CVE-2026-62814) and five EoP vulnerabilities with CVSSv3 scores of 7.8 (CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807 and CVE-2026-62812).CriticalMultiple CVEs | Microsoft Office SharePoint Spoofing, Remote Code Execution, Elevation of Privilege, Information Disclosure and Tampering VulnerabilitiesThis month's update includes patches for 29 CVEs affecting Microsoft Office SharePoint. Of the 29 CVEs, three were rated as critical and three were assessed as 'Exploitation More Likely.' A breakdown of the CVEs can be found in the table below:CVEDescriptionCVSSv3SeverityExploitability IndexCVE-2026-70306Microsoft Office SharePoint Spoofing9.3ImportantExploitation Less LikelyCVE-2026-62827Microsoft SharePoint Server Elevation of Privilege8.8CriticalExploitation Less LikelyCVE-2026-65665Microsoft SharePoint Server Remote Code Execution8.8CriticalExploitation More LikelyCVE-2026-64921Microsoft SharePoint Server Elevation of Privilege8.8CriticalExploitation Less LikelyCVE-2026-63514Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-64901Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-65658Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-65663Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-66805Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-66808Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-70321Microsoft SharePoint Remote Code Execution8.8ImportantExploitation Less LikelyCVE-2026-70324Microsoft SharePoint Elevation of Privilege8.8ImportantExploitation Less LikelyCVE-2026-70326Microsoft SharePoint Server Elevation of Privilege8.8ImportantExploitation Less LikelyCVE-2026-63520Microsoft SharePoint Server Remote Code Execution8.1ImportantExploitation More LikelyCVE-2026-57105Microsoft Office SharePoint Spoofing8.0ImportantExploitation Less LikelyCVE-2026-70355Microsoft SharePoint Server Elevation of Privilege7.3ImportantExploitation More LikelyCVE-2026-58639Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-62837Microsoft SharePoint Server Information Disclosure6.5ImportantExploitation Less LikelyCVE-2026-62839Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-63512Microsoft SharePoint Server Tampering6.5ImportantExploitation Less LikelyCVE-2026-63516Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-65660Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less LikelyCVE-2026-62829Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-62917Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-64897Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-64922Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less LikelyCVE-2026-64900Microsoft SharePoint Server Spoofing7.3ImportantN/ACVE-2026-64902Microsoft SharePoint Server Spoofing4.6ImportantN/ACVE-2026-64916Microsoft SharePoint Server Spoofing4.6ImportantExploitation UnlikelyTenable SolutionsA list of all the plugins released for Microsoft's August 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.Get more informationMicrosoft's August 2026 Security UpdatesTenable plugins for Microsoft August 2026 Patch Tuesday Security UpdatesJoin Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.
Analysis Summary
# Vulnerability: Windows Ancillary Function Driver (AFD) for WinSock Elevation of Privilege
## CVE Details
- **CVE ID:** CVE-2026-68820
- **CVSS Score:** 7.0 (Important)
- **CWE:** Not specified (Elevation of Privilege)
## Affected Systems
- **Products:** Windows Ancillary Function Driver (afd.sys) for WinSock.
- **Versions:** Multiple Windows OS versions (Standard Microsoft support lifecycle).
- **Configurations:** Systems running the Windows WinSock driver.
## Vulnerability Description
A local elevation of privilege (EoP) vulnerability exists in the Windows Ancillary Function Driver (AFD) for WinSock. The flaw allows a local attacker to execute code with elevated permissions. Successful exploitation provides the attacker with **SYSTEM** privileges, the highest user level in the Windows operating system.
## Exploitation
- **Status:** **Exploited in the wild** (Zero-day).
- **Complexity:** Low (Local access required).
- **Attack Vector:** Local.
## Impact
- **Confidentiality:** High (Full access to system data).
- **Integrity:** High (Ability to modify system files and settings).
- **Availability:** High (Ability to disable security software or crash the system).
## Remediation
### Patches
- Apply the August 2026 Microsoft Security Updates via Windows Update or the Microsoft Update Catalog.
### Workarounds
- No specific workarounds are provided; immediate patching is recommended due to active exploitation.
***
# Vulnerability: Windows Deployment Services TFTP Server Remote Code Execution
## CVE Details
- **CVE ID:** CVE-2026-62893
- **CVSS Score:** 9.8 (Critical)
- **CWE:** Not specified (Remote Code Execution)
## Affected Systems
- **Products:** Windows Deployment Services (WDS).
- **Versions:** Windows Server versions with the WDS role enabled.
- **Configurations:** Systems running the Trivial File Transfer Protocol (TFTP) Server component.
## Vulnerability Description
A critical remote code execution (RCE) vulnerability exists in the WDS TFTP Server. The flaw is triggered when the service improperly handles specially crafted packets.
## Exploitation
- **Status:** Not exploited in the wild (PoC not publicly mentioned, but rated "Exploitation More Likely").
- **Complexity:** Low.
- **Attack Vector:** Network (Remote, unauthenticated).
## Impact
- **Confidentiality:** High.
- **Integrity:** High.
- **Availability:** High.
## Remediation
### Patches
- Apply the August 2026 Microsoft Security Updates for Windows Server.
### Workarounds
- Disable the WDS TFTP service if it is not required for network booting or deployment operations.
***
# Vulnerability: Microsoft SharePoint Server Multiple Flaws (RCE/EoP)
## CVE Details
- **CVE ID:** CVE-2026-65665 (RCE), CVE-2026-62827 (EoP), CVE-2026-64921 (EoP)
- **CVSS Score:** 8.8 (Critical)
- **CWE:** Various (Spoofing, RCE, EoP, Information Disclosure)
## Affected Systems
- **Products:** Microsoft SharePoint Server.
- **Versions:** SharePoint Server 2016, 2019, and Subscription Edition.
## Vulnerability Description
SharePoint received patches for 29 CVEs this month. The most severe (CVE-2026-65665) allows for Remote Code Execution. Other flaws involve Elevation of Privilege and Tampering, which could allow an attacker to bypass security restrictions or gain administrative access to the SharePoint environment.
## Exploitation
- **Status:** Not exploited in the wild; CVE-2026-65665 is rated "Exploitation More Likely."
- **Complexity:** Medium.
- **Attack Vector:** Network.
## Impact
- **Confidentiality:** High.
- **Integrity:** High.
- **Availability:** High.
## Remediation
### Patches
- Install the specific security updates for the installed version of SharePoint Server.
***
## Summary of Other Notable August 2026 Zero-Days
1. **CVE-2026-62832 (CVSS 7.8):** Windows User Profile Service EoP. Publicly disclosed. Allows local attackers to gain **ADMINISTRATOR** privileges.
2. **CVE-2026-72971 (CVSS 5.5):** Windows Container Isolation FS Filter Driver Tampering. Publicly disclosed.
## Detection
- **Tenable Plugins:** Search for "August 2026 Patch Tuesday" updates in Tenable.sc, Tenable.io, or Nessus.
- **Audit:** Check for the presence of patched `afd.sys`, `unionfs.sys`, and SharePoint binaries.
## References
- Microsoft August 2026 Update Guide: hxxps://msrc[.]microsoft[.]com/update-guide/en-us/releaseNote/2026-Aug
- Tenable Analysis: hxxps://www[.]tenable[.]com/blog/microsofts-august-2026-patch-tuesday-addresses-398-cves-cve-2026-68820