Published Security3 min read
421 fixes in August, but only a handful set the patch order
Microsoft's August 2026 release closes 421 flaws, one of them an afd.sys zero-day Lazarus was already using for SYSTEM. Count of bugs is not the queue; exploit maturity and network reachability are.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Microsoft's August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical.
- One Windows vulnerability in the August 2026 release has been exploited in the wild by the Lazarus group to gain SYSTEM privileges.
- The August update is smaller than July's record-breaking release but still among Microsoft's largest Patch Tuesday batches.
- The August release includes a publicly disclosed Windows privilege escalation flaw with a proof of concept, a newly completed unauthenticated SharePoint remote code execution chain, and a potentially wormable Windows DNS Server flaw; the writeup does not assign CVE identifiers to the SharePoint chain or the DNS Server flaw.
- CVE-2026-62893 is an unauthenticated RCE flaw in the Windows Deployment Services TFTP server with a CVSS score of 9.8; TFTP normally runs on UDP port 69 and has no built-in authentication, and the issue is primarily an enterprise and school network problem that could enable lateral movement where WDS is deployed.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Microsoft's August 2026 Patch Tuesday closed 421 vulnerabilities, 62 of them rated Critical, and one of those was already in use by the Lazarus Group to obtain SYSTEM privileges [1][2]. Volume is not what should drive the rollout: three items in this batch come with either a live exploit, a finished chain, or a network path that needs no user in the loop [4].
Start with the one being fired at you. CVE-2026-68820 is a use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys) that lets an attacker win a race condition and take System [11]. Check Point attributes the exploitation to Lazarus and describes it as a continuation of Operation Dream Job, active since early 2026 against defense targets, mainly aerospace and aviation organizations in Europe and India, with victims named in France, Germany, Brazil and India [9][10]. In one chain, a delivered archive pairs a PDF viewer with a malicious DLL and an encrypted payload disguised as a PDF; DLL sideloading runs the Mistpen downloader in memory while a decoy job description occupies the screen, and the zero-day is used after reconnaissance and persistence, ahead of the ForestTiger backdoor [13]. A second chain uses a trojanized viewer called SecurityPDF that scans opened PDFs for a hidden marker and executes a new DLL implant, Troy, in memory with 17 operator commands including file upload and download, shell access and DLL injection [14][15]. Microsoft shipped the fix on August 11 and CISA added the CVE to the Known Exploited Vulnerabilities catalog with a two-week remediation window for federal agencies, which puts the deadline around August 25 [12][3].
After that, priority follows reachability. Malwarebytes flags a newly completed unauthenticated SharePoint RCE chain and a potentially wormable Windows DNS Server flaw in this release, though its writeup does not assign identifiers to either [4]. CVE-2026-62893, an unauthenticated RCE in the Windows Deployment Services TFTP server, carries a CVSS score of 9.8; TFTP listens on UDP port 69 with no built-in authentication, which makes this a lateral movement problem anywhere WDS is deployed in enterprise or school networks [5]. Then CVE-2026-62832, a publicly disclosed elevation of privilege in the Windows User Profile Service that maps to the issue researchers called LegacyHive, with a limited proof of concept released in July [6]. The demonstration is deliberately constrained and needs credentials for another user, but it shows a local authenticated attacker abusing registry hive handling to load someone else's hive, including an administrator's [7].
The Office bulk is not filler. Malwarebytes counted 48 RCE fixes across Excel, Word, Outlook, PowerPoint and the Office graphics component, about 11 percent of the month's total, all of it reachable by attachment or shared document [8][2]. Critical-rated bugs, for their part, are roughly 15 percent of the release [1].
One detail worth logging beyond patching: Check Point says the Lazarus command-and-control infrastructure runs on compromised Roundcube webmail and CMS deployments, many vulnerable to CVE-2025-49113, an RCE exploited since June 2025 [16]. Those servers host RelayShell, a previously undocumented PHP webshell that acts as a relay, passing commands and responses through plain text files rather than behaving like a conventional backdoor [17]. Check Point's advice to affected sectors is to prioritize this update, review the indicators of compromise, and treat unsolicited recruiter outreach as an unverified download request [18].
What to watch: whether the LegacyHive proof of concept gets extended past its credential requirement, whether the SharePoint chain shows up in mass scanning the way earlier SharePoint chains did, UDP 69 exposure at your own perimeter, and whether anyone publishes working code for the DNS Server bug [4][5][6].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft's August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical.
- [2]
One Windows vulnerability in the August 2026 release has been exploited in the wild by the Lazarus group to gain SYSTEM privileges.
- [3]
The August update is smaller than July's record-breaking release but still among Microsoft's largest Patch Tuesday batches.
- [4]
The August release includes a publicly disclosed Windows privilege escalation flaw with a proof of concept, a newly completed unauthenticated SharePoint remote code execution chain, and a potentially wormable Windows DNS Server flaw; the writeup does not assign CVE identifiers to the SharePoint chain or the DNS Server flaw.
- [5]
CVE-2026-62893 is an unauthenticated RCE flaw in the Windows Deployment Services TFTP server with a CVSS score of 9.8; TFTP normally runs on UDP port 69 and has no built-in authentication, and the issue is primarily an enterprise and school network problem that could enable lateral movement where WDS is deployed.
- [6]
CVE-2026-62832 is a publicly disclosed elevation of privilege vulnerability in the Windows User Profile Service that maps to the issue researchers called LegacyHive, for which a limited public proof of concept was released in July.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.comIonut ArghireAug 12Fresh Windows Zero-Day Exploited in North Korean Cyberattacks
- malwarebytes.comAug 12Patch Tuesday: Update now to fix 421 flaws, including three zero-days
Additional citations
- Malwarebytes
- Check Point, via SecurityWeek
- SecurityWeek



