{"id":1664,"date":"2026-08-13T08:47:59","date_gmt":"2026-08-13T08:47:59","guid":{"rendered":"https:\/\/newsraise.com\/in\/2026\/08\/13\/microsoft-august-2026-patch-tuesday-400-flaws-zero-day\/"},"modified":"2026-08-13T08:47:59","modified_gmt":"2026-08-13T08:47:59","slug":"microsoft-august-2026-patch-tuesday-400-flaws-zero-day","status":"publish","type":"post","link":"https:\/\/newsraise.com\/in\/2026\/08\/13\/microsoft-august-2026-patch-tuesday-400-flaws-zero-day\/","title":{"rendered":"Microsoft\u2019s August 2026 Patch Tuesday Tackles 400+ Flaws, Including Active Zero\u2011Day"},"content":{"rendered":"\n<!-- Quick Adsense WordPress Plugin: http:\/\/quickadsense.com\/ -->\n<div class=\"9fece8afa224fd09e54b043d0febfb58\" data-index=\"1\" style=\"float: none; margin:10px 0 10px 0; text-align:center;\">\n<script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js\"><\/script>\r\n<!-- NR ATF -->\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block\"\r\n     data-ad-client=\"ca-pub-8898941184964366\"\r\n     data-ad-slot=\"4839033563\"\r\n     data-ad-format=\"auto\"\r\n     data-full-width-responsive=\"true\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script>\n<\/div>\n<p>Microsoft announced its August 2026 Patch Tuesday update on 11\u202fAugust, delivering fixes for more than 400 security weaknesses across Windows and a range of other supported products. Among the corrections are three zero\u2011day vulnerabilities that were already being exploited or publicly disclosed before the patches became available.<\/p>\n<h2>Scale and composition of the update<\/h2>\n<p>The August bundle is one of the larger monthly releases from the software giant, though its headline count is lower than the unusually high July update, which some analysts estimated at over 600 flaws. The current release contains 42 vulnerabilities classified as Critical. Of those, 37 could enable remote code execution, while the remaining five are privilege\u2011escalation bugs.<\/p>\n<p>Microsoft\u2019s tally of roughly 400 issues does not encompass every flaw addressed by the company in August. Separate patches for Azure, Entra, Teams, Office, Power\u202fApps and the Mariner Linux distribution were issued earlier in the month and are excluded from the Patch Tuesday count. This distinction matters because many cloud\u2011based fixes are applied automatically, whereas updates for on\u2011premises Windows endpoints still require manual testing and deployment by enterprise IT teams.<\/p>\n<h2>Highest\u2011priority zero\u2011day: CVE\u20112026\u201168820<\/h2>\n<p>The most urgent flaw in the August cycle is identified as CVE\u20112026\u201168820, an elevation\u2011of\u2011privilege vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys). The driver sits in kernel mode and mediates network operations between user\u2011mode Winsock applications and the underlying networking stack. Microsoft described the defect as a use\u2011after\u2011free condition, where the driver continues to reference memory that has already been released.<\/p>\n<p>Exploitation of the bug requires an attacker who is already authenticated on the target system and can execute a specially crafted program. The malicious code triggers a race condition in the driver, allowing the attacker to gain SYSTEM\u2011level privileges without any further user interaction. Because the vulnerability operates at the kernel level, it can be used to bypass security controls, steal credentials and establish persistent footholds.<\/p>\n<p>Check Point researchers Moshe Marelus and David Driker discovered and reported CVE\u20112026\u201168820. Their investigation linked active exploitation of the flaw to the North Korean state\u2011sponsored group commonly known as Lazarus. The group leveraged the vulnerability as part of a broader campaign that began with fraudulent employment offers.<\/p>\n<h2>Lazarus campaign and the FudModule rootkit<\/h2>\n<p>According to Check Point, the attackers approached potential victims with fake job opportunities, a social\u2011engineering tactic that has appeared in numerous North Korean operations targeting developers, cryptocurrency firms and defense\u2011sector employees. Once a target accepted the offer, they were prompted to open a file, run a project or install software that appeared legitimate.<\/p>\n<p>When the malicious code executed with ordinary user rights, it invoked CVE\u20112026\u201168820 to elevate privileges and install a new variant of FudModule, a sophisticated kernel\u2011mode rootkit previously associated with Lazarus espionage activities. FudModule operates at a level of the operating system that can interfere with security products, hide malicious processes, block telemetry and protect other malware components from removal.<\/p>\n<p>The combination of social engineering and a previously unknown kernel flaw makes this attack chain noteworthy. It demonstrates how Lazarus can turn an initial low\u2011privilege compromise into a high\u2011privilege, stealthy intrusion that is difficult to detect with conventional endpoint tools.<\/p>\n<h2>Other zero\u2011days and notable fixes<\/h2>\n<p>In addition to the WinSock driver flaw, the August update addresses two other vulnerabilities that were publicly known before patches were released. One is a Windows User Profile Service issue tied to the \u201cLegacyHive\u201d technique, a method previously disclosed in security research. The second is a tampering vulnerability in the Windows Container Isolation file\u2011system filter driver, which could allow an attacker to modify container files.<\/p>\n<p>Microsoft notes that the 400\u2011flaw estimate reflects only the vulnerabilities released as part of the Patch Tuesday cycle. It does not count flaws that fall into multiple technical categories or that were published earlier in the month, nor does it include browser issues inherited from Chromium.<\/p>\n<h2>Implications for enterprise security teams<\/h2>\n<p>The sheer volume of patches underscores the growing operational pressure on organizations tasked with managing updates across diverse environments. While the headline number provides a sense of scale, security professionals are urged to prioritize based on the location, exploitability and exposure of each flaw. For example, an actively exploited privilege\u2011escalation bug on employee workstations may present a more immediate risk than a remote\u2011code\u2011execution vulnerability affecting a component that is disabled or isolated in a given deployment.<\/p>\n<p>Microsoft\u2019s increasing reliance on artificial intelligence to discover weaknesses across its expanding codebases is intended to accelerate vulnerability identification, but it also adds complexity to the patch\u2011management lifecycle. Enterprises must continue to test and roll out updates promptly, especially for critical components such as the afd.sys driver that can be weaponized by advanced threat actors.<\/p>\n<p>Finally, organizations that fall within Lazarus\u2019s traditional target set\u2014software developers, cryptocurrency enterprises, defense contractors and other technology\u2011focused entities\u2014should conduct thorough investigations for signs of compromise even after applying the patch. The update closes the vulnerability, but it does not automatically remove any malicious code that may have been installed beforehand.<\/p>\n<p>Overall, Microsoft\u2019s August 2026 Patch Tuesday reflects both the breadth of modern software attack surfaces and the necessity for vigilant, timely remediation across the enterprise ecosystem.<\/p>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>Microsoft\u2019s August 2026 Patch Tuesday release patches more than 400 vulnerabilities, among them three zero\u2011days, with a critical kernel flaw linked to North Korean Lazarus attacks.<\/p>\n","protected":false},"author":3,"featured_media":1665,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[299],"tags":[1510,1507,1511,1508,1509],"class_list":["post-1664","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-lazarus","tag-microsoft","tag-patch-tuesday","tag-security","tag-zero-day","entry"],"_links":{"self":[{"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/posts\/1664","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/comments?post=1664"}],"version-history":[{"count":0,"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/posts\/1664\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/media\/1665"}],"wp:attachment":[{"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/media?parent=1664"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/categories?post=1664"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsraise.com\/in\/wp-json\/wp\/v2\/tags?post=1664"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}