Particle.news

Microsoft Ships August Patch Tuesday Fixes for About 400 Vulnerabilities Including an Exploited Zero‑Day

The bundle forces defenders to move from score-based triage to exploit‑aware, risk‑based patching to protect exposed services.

Overview

  • Microsoft released its August Patch Tuesday updates on Tuesday, August 11, delivering cumulative packages for Windows 11 and Windows 10 that address roughly 398–421 CVEs and include feature updates.
  • The release closes an actively exploited kernel use‑after‑free in the WinSock driver afd.sys (CVE‑2026‑68820) that researchers say was used by North Korean‑linked actors to deploy a kernel‑mode rootkit and that CISA added to its Known Exploited Vulnerabilities list.
  • Security teams are urged to prioritize fixes for the afd.sys zero‑day, several unauthenticated remote‑code execution flaws that can be wormable (Windows DNS Server, WDS/TFTP, Microsoft QUIC, HPC Pack), and any publicly disclosed bugs when triaging patches.
  • Researchers have published proof‑of‑concept code and reported patch‑bypass claims for some issues, while Microsoft split fixes for a SharePoint exploit chain across July and August, increasing the need to test updates before broad deployment.
  • The high patch volume follows a recent surge in AI‑assisted vulnerability discovery, which speeds flaw finding and raises the operational need for continuous inventory, tested automated patch pipelines, backups, and exploit‑aware risk management.