Published Security3 min read
Microsoft Shipped 419 Fixes and Stopped Listing Them. Two Outlets Counted Differently.
The August Patch Tuesday is the second in a row without an itemized CVE list.
Not a builder's beat, but builders have a standing stake in it.See today for builders
What happened
- Microsoft's August Patch Tuesday released fixes for 419 security vulnerabilities according to the company's August release notes, one of the largest monthly counts on record.
- Microsoft's August release notes describe the update as addressing 62 critical and 357 important-rated issues.
- KrebsOnSecurity reported Microsoft released updates to remedy at least 398 security vulnerabilities, of which 42 earned Microsoft's critical rating.
- The two published counts differ by 21 in the total number of vulnerabilities (419 versus 398) and by 20 in the number rated critical (62 versus 42).
- As with the previous month, Microsoft no longer lists the individual CVEs, having replaced the previously itemized batch with a summary table showing a count of bugs by product family alongside a "Notable CVEs" section.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Microsoft's August Patch Tuesday addressed 419 vulnerabilities according to the company's release notes, and for the second month running the Security Updates page carried no itemized CVE list, replaced by a summary table of bug counts by product family plus a "Notable CVEs" section [1][5]. That matters less because of the number than because of what the number is attached to: nothing you can diff, sort, or feed into a ticketing queue without reconstructing it yourself from advisory feeds [6].
The evidence for that is in the coverage. Recorded Future News, citing the release notes, reported 419 fixes broken into 62 critical and 357 important [1][2]. KrebsOnSecurity reported "at least 398" flaws, of which 42 were rated critical [3]. That is a gap of 21 in the total and 20 in the critical count between two careful outlets reading the same vendor on the same day [4]. Last month's release is described as 622 by one and "more than 570" by the other [9]. When two trackers cannot agree on the denominator, no downstream SLA that reads "patch all critical vulnerabilities within N days" means anything precise.
The volume itself is roughly five times a typical pre-AI month [7]. Microsoft went from 137 patches in May, when it said the industry had reached a point "where AI-powered vulnerability discovery stops being speculative and starts being an engineering problem," to 206 in June and 622 in July [8][9]. Those four months alone total 1,384, past the company's previous annual record of around 1,250 [10].
The triage picture underneath is narrower than the headline. Three flaws are zero-days, two publicly disclosed before the patches shipped, and one seen exploited: CVE-2026-68820, a privilege escalation bug in afd.sys, the driver behind Windows socket connections on effectively every endpoint, per the security firm Automox [11][12]. Automox's Landon Miles wrote that it "isn't a front-door bug" but step two in a chain after a low-privilege foothold, with its 7.0 score reflecting the high attack complexity of a race condition [13]. Microsoft tied the exploitation to a Lazarus Group campaign against applicants for defense, aerospace and aviation jobs, using PDFs paired with a trojanised reader [14]. CVE-2026-62832, in the Windows User Profile Service, is flagged likely to be exploited and may correspond to the LegacyHive proof of concept from the researcher known as Nightmare Eclipse, published hours after July's Patch Tuesday amid a months-long dispute over Microsoft's disclosure and bounty practices [15]. The third, CVE-2026-72971, is low-impact local tampering that Microsoft judges unlikely to be exploited [16].
So one actively exploited bug out of roughly 400, which is Tyler Reguly of Fortra's point: the count should not panic anyone into patching faster than they can test, and security leaders should be asking their teams how workflows are actually changing [17]. Automating the testing away is not currently an option. Researchers at 1Password found that LLMs asked to patch newly disclosed complex vulnerabilities produced fixes that failed, introduced a new weakness, or both, more than half the time [18]. SANS Technology Institute president Ed Skoudis said his team gets good results with humans in the loop, and that one-shot AI patching should not be expected to work reliably [19].
What to watch: whether Microsoft restores machine-readable parity between the summary page and the advisory feeds, and how third-party trackers reconcile their counts. Adobe has already moved to twice-monthly bulletins on the second and fourth Tuesday, and Cisco, Google, Mozilla and Oracle are shipping more often and in larger batches [20]. Britain's NCSC warned before the surge that organizations needed to prepare for a new tempo [21], and in June the Five Eyes said frontier models would fundamentally transform offensive and defensive cyber capability on a timeline of "months," not years [22]. Widespread exploitation of the surge has not been observed yet [23], which is the window in which to fix the pipeline rather than the patch queue.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft's August Patch Tuesday released fixes for 419 security vulnerabilities according to the company's August release notes, one of the largest monthly counts on record.
ReportedSource: Recorded Future News (The Record), citing Microsoft's August release notesView cited source - [2]
Microsoft's August release notes describe the update as addressing 62 critical and 357 important-rated issues.
- [3]
KrebsOnSecurity reported Microsoft released updates to remedy at least 398 security vulnerabilities, of which 42 earned Microsoft's critical rating.
- [5]
As with the previous month, Microsoft no longer lists the individual CVEs, having replaced the previously itemized batch with a summary table showing a count of bugs by product family alongside a "Notable CVEs" section.
- [6]
The new clustered format of the Security Updates page risks making triage more complex; defenders and third-party trackers must now piece together the full picture from underlying advisory feeds themselves and figure out what needs to be patched first.
- [7]
This month's update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- krebsonsecurity.comBrianKrebsAug 11Microsoft Plugs Nearly 400 Security Holes
- therecord.mediaAug 12Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
Additional citations
- Recorded Future News (The Record), citing Microsoft's August release notes
- The Record, citing Microsoft's August release notes
- KrebsOnSecurity
- The Record



