August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw
Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971. This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw. The Readiness team has provided a helpful infographic on the deployment risks for this Microsoft August update. Known issues Both August client and server-side updates ship with empty known-issues lists. This may change over the coming days so checking back to the Microsoft Security Update Guide (MSRC) may be prudent. July’s open items have all closed: the Dell/Intel driver hold, the mid-July WSUS sync degradation, and the Emoji Panel GIF outage (August swaps in GIPHY). On the server side, WSUS synchronisation error details stay suppressed. The August Windows Server 2025 (KB5120233) and 2022 (KB5120242) updates still list this, the detail pane removed to address a remote code execution flaw CVE-2025-59287, with no published workaround. One July item has been dropped from the documentation without a resolution note: the Windows Server 2022 BitLocker recovery prompt on first restart, for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team recommends that all recovery keys are (easily) retrievable before restarting freshly patched servers. Major revisions and mitigations Between the July and August Patch Tuesdays (15 July to 10 August), the MSRC Security Update Guide revised 534 CVEs. Almost all these changes (458) were routine Microsoft Edge and Chromium re-publications – none of which required customer action. That leaves 76 touching Microsoft’s own products, 60 of them flagged customer action required, including: Windows storage and file system: four NTFS entries, all three July ReFS elevation-of-privilege flaws, and two Brokering File System fixes. Identity and federation: six AD FS denial-of-service CVEs, plus two Azure Active Directory entries. Developer runtimes: nine .NET and .NET Framework CVEs, with PowerShell and ASP.NET Core alongside. The Readiness team has reviewed the 751 published updates, and it appears that Microsoft has not published any mitigations for updates in this August release. Windows lifecycle and enforcement updates Microsoft has not published any service or enforcement deadlines for this August. The 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November; dates below come from the linked Microsoft lifecycle pages. Windows Server 2012 and 2012 R2 ESU hits year three. Windows 10 2016 LTSB reaches the end of extended support, and Office LTSC 2021 and retail Office 2021 all end 13 October. Windows Server 2022 drops to extended support on 13 October 2026, security-only to 14 October 2031. One diary note: Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, two Patch Tuesdays out. Microsoft’s August 2026 Patch Tuesday is a security-only release: 109 Windows test-guidance entries, four High Risk (July had 14). Printing and fonts lead: win32kfull.sys is the most-patched binary at seven entries and carries three of the four High Risk flags (32-bit printing on 64-bit Windows and font rendering); the Remote Desktop client carries the fourth. The testing guidance below works through each product and feature grouping. Printing, fonts and graphics Three of the four High Risk flags sit in win32k and touch print or font paths: 32-bit application printing on 64-bit Windows (two) and font rendering (one). GDI+, the Windows Imaging Component, and the kernel graphics driver (dxgkrnl.sys, five entries) change alongside; estates with 32-bit line-of-business printing or font-heavy documents take this first. Print from your 32-bit applications to physical and virtual (PDF or XPS) printers, using text-heavy, graphics-heavy, and multi-page documents, and repeat after each relaunch, orientation, scaling, and resolution change. Render varied fonts, sizes, and styles across browsers, Office, PDF viewers, and Notepad, and confirm Print Preview matches the printed page – watch for clipping, distortion, or missing glyphs. Copy and paste images between Paint, Word, and Excel at different bit depths, and open EMF and TIFF files. Exercise the graphics kernel: full-screen DirectX, multi-monitor hot-plug, resolution, HDR, and DPI changes, and sleep/resume. Remote desktop and remote access The RDP client carries the fourth High Risk flag; the fixes touch every redirection path and multi-session behaviour. RemoteApp, the display pipeline, and the RRAS and SSTP VPN stack change alongside. Open several concurrent RDP sessions, enable printer, clipboard, audio, drive, and smart card redirection together, and exercise each across the sessions, confirming none interferes with another. Disconnect and reconnect a session, confirm redirected devices and drives reattach, and test a RemoteApp end to end. Configure a standard client VPN and an SSTP VPN over HTTPS and confirm sustained connections across reconnects and a restart. Storage, file sharing and virtualization The SMB client and server, NTFS and UDFS, the virtualised file layers (Cloud Files, Projected File System, Work Folders), and the platform stack (Hyper-V, virtual TPM, USB, and Windows Installer) all change. Standard Risk. Connect to SMB shares (including RDMA, leases, and Continuous Availability), copy large sets both ways, and interrupt and reconnect a session; exercise NTFS extended attributes, UDF mounts, and cloud-file hydrate and dehydrate. Create, checkpoint, and export a Generation 2 Hyper-V VM, enable a virtual TPM and BitLocker, and connect USB storage and MIDI devices. Install, repair, and uninstall an MSI package, and confirm UAC elevation still prompts. Telephony, networking and core services TAPI is the busiest component (11 entries) but carries only parity fixes; the rest spans TCP/IP, HTTP.sys, Windows Firewall, Bluetooth, wired 802.1X, and message queuing. Broad and shallow. Exercise TAPI line status and dialling locations against a shared line, and verify HTTP.sys under IIS over HTTP/1.1, HTTP/2, and HTTP/3. Confirm TCP/IP IPsec tunnels on IPv4 and IPv6, toggle Windows Firewall rules across a restart, pair a Bluetooth headset, authenticate wired 802.1X, and validate MSMQ send and receive. Office and SharePoint This August patch cycle affects click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office with the following updates: On MSI Office 2016, apply the client updates: Access (KB5002813), the ACE database engine (KB5002832), the Office proofing and UI components (KB5002791, KB5002795), Outlook (KB5002755), VBA (KB5002900), and Word (KB5002901), then exercise macros, external data, embedded objects, and line-of-business add-ins. On SharePoint Server, patch 2016, 2019, and Subscription Edition, then check browser-based editing; mind the rollback rules – server updates cannot be uninstalled and always require a reboot. Microsoft Exchange Server On-premises Exchange takes a security update this month, seven CVEs across Exchange Server 2016, 2019, and Subscription Edition: one critical elevation of privilege and six important, spanning further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass. Apply the update from an elevated command prompt: an un-elevated run leaves Exchange services partially patched and broken. Then confirm every Exchange service returns and that the server reports healthy. Exercise mail flow end to end: send and receive internal and external mail, drain the transport queues, and check connectors and transport rules; confirm Outlook (MAPI over HTTP), Outlook on the web, and the Exchange admin centre for sign-in and core actions. Confirm Autodiscover and free/busy resolve, test any hybrid connection to Exchange Online, and plan for the reboot the update requires – validate in a maintenance window before production. Developer tools: .NET The developer estate gets a broad, low-drama sweep; no SQL Server this month. Both the .NET Framework (Windows Server 2012 to Windows 11 26H1 and Server 2025) and the modern runtime and SDK patch, including WPF and WinForms. Install the .NET Framework and modern .NET runtime and SDK updates, run a representative set of WPF, WinForms, web, and command-line applications, confirm normal behaviour, and build and run a .NET project to check for regressions. The Readiness team recommends the following priorities for your larger enterprise deployments: Start with printing and fonts: three of the four High Risk flags sit in win32k, so regress 32-bit printing, PDF and XPS export, font rendering, and Print Preview before anything else. Take Remote Desktop next, the fourth High Risk flag, across the redirection paths, concurrent sessions, reconnects, RemoteApp, and SSTP VPN. Give the busy but lower-risk areas a smoke pass: Telephony, the graphics kernel, DNS and DHCP, Active Directory, and the SMB stack. Close out the rest: Office spans MSI 2016, SharePoint and Microsoft 365 Apps this month (Click-to-Run is in scope, unlike July), and .NET is a representative-application check. Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings. Browsers After July’s 46-strong Microsoft Edge (Chromium-based) haul, the browser family has nothing to report: August’s Security Update Guide carries no Edge-specific CVEs at all. It’s Margarita time – look busy or look elsewhere for patch-related testing and deployments. Microsoft Windows Windows carries the bulk again: 233 CVEs, 18 critical, the rest important bar one moderate. Elevation of privilege leads by volume (143 entries), but all but two of the 18 are rated as critical remote code execution vulnerabilities, on the network-facing server roles. DHCP and DNS lead the critical-rated issues. Windows DHCP Server takes 14 CVEs, the busiest component by far, topped by a critical remote code execution flaw (CVE-2026-62823, “Exploitation More Likely”), with DHCP Client adding four more. Windows DNS Server is the headline RCE risk: six entries, four of them critical (CVE-2026-62878, CVE-2026-62817, CVE-2026-62820, CVE-2026-65789), reaching back to Server 2012. Patch the resolvers alongside the DHCP boxes. A wider critical cluster. Beyond DNS, critical-rated issues also reach Microsoft QUIC, RRAS, the iSCSI Target Service, the WDS TFTP Server, the Remote Desktop Client, GDI+ graphics and Active Directory Certificate Services; domain controllers take priority, and Print Spooler and WSUS are for once absent. Most-patched tally. DHCP Server leads (14, one critical), Win32k next (13 across two groupings), then the Telephony Service (11), the DNS client resolver (10), Windows Installer (nine), and the Windows Kernel and NTFS (eight each). Add this Windows update to your Patch Now schedule, with your DHCP and DNS servers updated first. Microsoft Office Microsoft released 120 Office CVEs this month, 24 of them critical, remote code execution the through-line (62 entries). The packaging work sits on MSI Office 2016 and the SharePoint farms, but the exposure is overwhelmingly Click-to-Run: 89 of the 120 list Microsoft 365 Apps for Enterprise as affected, 20 of them critical, straight through the update channel. Office clients – the critical RCE runs across Office, Word and Excel, mostly in document-rendering paths that fire on preview or open. The top-rated critical client entry, CVE-2026-70130, lists Microsoft 365 Apps among its affected builds, so Click-to-Run estates are squarely in scope rather than sitting this one out, as they could in July. SharePoint Server – three critical-rated vulnerabilities on the on-premises farms, led by CVE-2026-65665, an RCE rated “Exploitation More Likely” (2019 and Subscription Edition), with two critical elevation-of-privilege entries behind it; a separate SharePoint Online spoofing flaw is fixed service-side. Nothing in Office is exploited this month, but that critical SharePoint RCE and 20 Click-to-Run critical-rated vulnerabilities argue against waiting. Add the August Office and SharePoint updates to your Patch Now schedule. Microsoft Exchange and SQL Server Exchange Server has seven CVEs across Exchange Server 2016, 2019 and Subscription Edition, as four build-specific updates (KB5121573 through KB5121576). One is critical and six important; none is disclosed or exploited, but Exchange is internet-facing, so we would not wait. Exchange Server (on-premises) – the critical entry is an elevation of privilege (CVE-2026-62911); the heaviest of the rest is a remote code execution (CVE-2026-62913). Apply it from an elevated command prompt and plan for the reboot (the test-guidance section covers mail-flow). Subscription Edition is the go-forward release; 2016 and 2019 still being carried is a reprieve, not grounds to defer migration. SQL Server – nothing to install. On-premises SQL Server ships nothing; the only SQL-branded entries are cloud-side Azure SQL fixes, resolved service-side. Add the on-premises Exchange update to your Patch Now schedule; SQL Server does not require anything this month. Microsoft developer tools Microsoft released 23 CVEs across its developer tooling this month, all rated as important: 13 in .NET and the .NET Framework, and 10 across Visual Studio Code and its Copilot extensions. Microsoft .NET and .NET Framework – the runtime and framework are the focus this month, led by two remote code execution entries (CVE-2026-62897, .NET Framework, and CVE-2026-70354, .NET Core). The Framework rollups span Windows Server 2012 to Windows 11 26H1 and Server 2025; Visual Studio 2022 17.14 and 2026 18.8 take their exposure through the bundled runtime. Visual Studio Code and Copilot – have three remote code execution entries and security feature bypasses across the Python extension, Copilot Chat and the core editor. Add these developer-focused updates to your standard release schedule, behind this month’s Windows and Office priorities. Adobe (and third-party updates) Unusually, Adobe published an early-August emergency fix for a maximum-severity Adobe flaw (CVE-2026-48449), an incorrect authorisation that runs code with no user interaction. This makes this an Adobe “whatever you have installed” Patch Now moment due to how Adobe tends to share code between products. This August, there were two third-party flaws on Microsoft’s third-party list: the Trusted Computing Group’s TPM 2.0 reference-code bugs CVE-2026-6726 and CVE-2026-6727, both Important and issued by MITRE. If unpatched, a local attacker with TPM command access can work back to keys the chip should keep sealed, up to the RSA Endorsement Key behind device attestation. This completely defeats the purpose of the TPM chip – and, some would say, of migrating to Windows 11. Sorry, not sorry.
This is a summary aggregated from Computerworld. Read the complete article on the original site:
Read full article at Computerworld