Microsoft's August Update Fixes Nearly 400 Flaws, One Already Under Attack
Microsoft has released its August security update, patching 398 vulnerabilities across Windows and supported software. Of these, 42 were rated critical, meaning attackers could potentially exploit them to take remote control of a Windows machine with little or no user interaction.
One flaw, CVE-2026-68820, is already being actively exploited. It affects afd.sys, a core Windows driver that handles network socket connections on nearly every Windows endpoint. Security firm Automox notes that this is not typically an entry point for attackers; rather, it is used after an initial foothold, often gained through phishing, to escalate privileges and fully compromise a device. A second flaw, CVE-2026-62832, in the Windows User Profile Service, has been flagged by Microsoft as likely to be exploited and may be linked to a recent public disclosure. A third issue, CVE-2026-72971, was also publicly disclosed but is considered low risk.
This month's update continues a trend of unusually large patch releases, following a record-breaking batch of over 570 fixes in July. Experts say the rising numbers are partly linked to AI-assisted vulnerability discovery, suggesting businesses should expect large monthly patch batches to become the norm.