Overview
- Microsoft released its August Patch Tuesday updates on Tuesday, August 11, delivering cumulative packages for Windows 11 and Windows 10 that address roughly 398–421 CVEs and include feature updates.
- The release closes an actively exploited kernel use‑after‑free in the WinSock driver afd.sys (CVE‑2026‑68820) that researchers say was used by North Korean‑linked actors to deploy a kernel‑mode rootkit and that CISA added to its Known Exploited Vulnerabilities list.
- Security teams are urged to prioritize fixes for the afd.sys zero‑day, several unauthenticated remote‑code execution flaws that can be wormable (Windows DNS Server, WDS/TFTP, Microsoft QUIC, HPC Pack), and any publicly disclosed bugs when triaging patches.
- Researchers have published proof‑of‑concept code and reported patch‑bypass claims for some issues, while Microsoft split fixes for a SharePoint exploit chain across July and August, increasing the need to test updates before broad deployment.
- The high patch volume follows a recent surge in AI‑assisted vulnerability discovery, which speeds flaw finding and raises the operational need for continuous inventory, tested automated patch pipelines, backups, and exploit‑aware risk management.