Overview
- Microsoft released the August Patch Tuesday updates on Tuesday, Aug. 11, 2026, delivering roughly 398–421 fixes across Windows and related products.
- The bundle includes an actively exploited use‑after‑free in the kernel driver afd.sys (CVE‑2026‑68820) that allows a locally authenticated attacker to elevate to SYSTEM without user interaction.
- Several high‑severity remote code execution flaws affect remotely reachable services such as Windows DNS Server, Windows Deployment Services TFTP, Microsoft QUIC, and HPC Pack and should be prioritized after the exploited driver bug.
- Windows 11 cumulative KB5121003 and Windows 10 ESU KB5120249 are rolling out as mandatory updates, add user-facing fixes and offline .msu installers, and come in much larger package sizes that may require staged testing.
- Security teams are urged to triage by exploit status and network reachability, use known‑exploited and risk scores to prioritize, test updates before broad deployment, and maintain backups because AI‑driven discovery has sharply increased monthly vulnerability volumes.