CyberSecurity

Microsoft’s August Patch Drop: 398 Flaws Fixed, One Zero-Day Under Active Attack

Published

on

A Record-Breaking Year for Patch Tuesday

Microsoft’s August Patch Tuesday is here, and it’s a big one. The company has released fixes for at least 398 security vulnerabilities across Windows and supported software. That’s nearly double June’s then-record batch of around 200 fixes.

This month’s haul doesn’t quite top July’s staggering 570-plus updates, but it’s a clear sign that the era of small, manageable patch bundles is over. Microsoft attributes this surge to vulnerability discoveries powered by artificial intelligence. Security experts agree: get used to seeing hundreds of CVEs every month.

Critical Flaws and the Actively Exploited Zero-Day

Of the 398 flaws patched today, 42 are rated critical. That means they’re severe enough for attackers to potentially gain remote control over a Windows machine with minimal user interaction.

The one actively exploited zero-day is CVE-2026-68820, a privilege escalation vulnerability in afd.sys, the Windows socket driver. Landon Miles at Automox describes it as “the driver behind Windows socket connections on effectively every endpoint.”

Miles explains the attack chain: “An attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box.” The vulnerability has a CVSS score of 7.0, reflecting the high attack complexity. Race conditions make the exploit fiddly, but someone is clearly landing it anyway.

Other Flaws to Watch

Two other vulnerabilities were publicly disclosed before today. CVE-2026-62832, a privilege escalation flaw in the Windows User Profile Service, is labeled likely to be exploited. It may be linked to the recent “LegacyHive” disclosure from researcher Nightmare Eclipse.

The other, CVE-2026-72971, is a low-impact local tampering bug that Microsoft considers unlikely to be exploited.

AI: Finding Bugs Faster Than We Can Fix Them

Microsoft isn’t alone in this AI-driven patch deluge. Adobe has moved to twice-monthly security bulletins. Cisco, Google, Mozilla, and Oracle are all shipping updates more frequently and in larger volumes.

AI is undeniably good at finding security holes. But fixing them? That’s another story. Researchers at 1Password tested how well large language models generate patches for complex, newly disclosed vulnerabilities. The results were sobering: more than half the time, the AI-generated patches either failed to fix the flaw or introduced a new weakness. Sometimes both.

Ed Skoudis, president of the SANS Technology Institute, has seen promising results with AI-assisted patching — but only with humans in the loop. “AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” he wrote. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify.”

Should You Rush to Patch?

With nearly 400 fixes, it’s tempting to deploy everything immediately. Tyler Reguly at Fortra advises against panic. Only one of these bugs is known to be actively exploited right now.

Reguly suggests security leaders check in with their teams about workload and workflow. “There’s no need to rush these updates,” he says. “You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”

That means testing patches before deployment, especially in production environments. A broken patch can be worse than the vulnerability it’s meant to fix.

Practical Steps for Home Users and Admins

  • Back up your system before applying this month’s updates. The day after Patch Tuesday is sometimes called “Reboot Wednesday,” but it’s wise to wait a few days.
  • Prioritize the zero-day: CVE-2026-68820 should be at the top of your list.
  • Test before deploying in enterprise environments. Microsoft sometimes needs a couple of days to iron out misbehaving patches.
  • Monitor the SANS Internet Storm Center for a clickable, per-patch breakdown by severity and urgency.

For more on how to handle these massive update bundles, check out our guide to Windows update management best practices. And if you’re worried about AI-generated vulnerabilities, read about AI security risks in 2026.

The bottom line: patch, but patch smart. The volume is only going to grow.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version