Security1 distinct publisher3 min readPublished
Only one of the 398 CVEs Microsoft fixed in August was confirmed exploited, and the SharePoint chain now hitting servers turns on a July patch, which puts exposure on cycle lag rather than on ranking.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The chain in active use against SharePoint servers spans two release cycles, and that is what makes it instructive: the fix for the authentication bypass half was already a month old when the remote code execution half shipped [7]. A team that scored the August release perfectly and had not yet cleared July was still reachable. There was nothing to prioritise, because the item was not on the current list.
The volume argues the same way. Of 398 CVEs, one arrived with confirmed exploitation and two more were public before their patches [3], which leaves 397 with no exploitation signal on release day [4] and three, under one percent of the month, with any public head start at all [5]. The 42 Criticals are 10.6 percent of the total [2][6]. Sort that pile however you like; the number of binaries to regression test and the number of reboots to schedule does not move. The column credits AI vulnerability discovery for the volume and notes that the matching AI-driven attack wave has been slow to appear [14], so the input side is scaling while the exploitation rate stays flat.
Which is why the author of the Help Net Security forecast, who published a prioritisation methodology a month earlier [15], now names time to test and deploy as the constraint [8]. Microsoft's Igor Sahknov, corporate vice president for Azure Networking, describes the same problem as a collapsing patch window and proposes the network as a control plane, writing that "the objective is not to avoid patching" but "to create a meaningful layer of defense during the period when patching has not yet been completed" [9]. Read literally, that is a case for segmentation as a timer, bought to cover deployment rather than to replace it.
October is the hard date. October Patch Tuesday brings the final updates for Windows 11 Version 24H2 Home and Professional, and ends ESU for Server 2012 and 2012 R2 and for Exchange Server 2016 and 2019 [12]. Those systems leave the patch queue and enter the migration or mitigation queue.
Two items in August are worth separating. Three Critical CVEs carried CVSS 10.0 and Microsoft remediated them in its own cloud operations: CVE-2026-65816 and CVE-2026-69555 in Azure Arc, CVE-2026-65801 in Exchange Server Online [11]. They score highest and require nothing from you. CVE-2026-62911 scores lower at 8.0, is rated Critical, is not known exploited, and per Microsoft lets an attacker take over the mailboxes of all Exchange users to read mail, send mail and download attachments [10]. That one is on-premises work with a mail-wide blast radius.
The evidence has limits. The column does not identify the single exploited CVE, attributes the SharePoint chain to no actor, and puts no numbers on how long testing takes or how wide current maintenance windows are [17]. What supports the case for a wider window is two practitioner judgements pointing the same way plus one live chain whose first fix had been available since July. That justifies moving the window, and leaves the size of the move to your own change-failure data.
Ranked by verification strength, evidence, and original report placement.
August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs.
The August 2026 total broke down as 42 rated Critical, 355 rated Important and 1 rated Moderate.
Despite the volume, only one August 2026 vulnerability was confirmed actively exploited in the wild, and two more were publicly disclosed ahead of the released patches.
SharePoint vulnerabilities CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and then remote code execution to actively exploit SharePoint servers; the fixes were released on July and August Patch Tuesdays respectively.
The forecast's author states that the greatest challenge in testing and deploying patches is time.
Igor Sahknov, Microsoft corporate vice president for Azure Networking, published an article on the collapse of the patch window proposing the network as a control plane, stating: 'The objective is not to avoid patching. The objective is to create a meaningful layer of defense during the period when patching has not yet been completed.'
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Public exploit code for CVE-2026-62911 is outpacing patching on 21,899 exposed Exchange servers3 distinct publishers
security
SharePoint RCE detections keyed to one exploit will miss the other, after CVE-2026-63520 leaks early2 distinct publishers
security
Defender's SYSTEM race is back: ShieldBreak PoC says Microsoft's July fix never held6 distinct publishers
build
ShieldBreak: a Defender-to-SYSTEM PoC that your last patch cycle did not stop1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One practitioner's column, no advisory a reader can open
The 398 total, the 42/355/1 split and the single confirmed exploitation all rest on the same monthly Help Net Security column, which cites no Microsoft advisory, no KEV entry and no second count. The CVE-level specifics are precise enough to be checkable — identifiers, CVSS values, the July-versus-August split on the SharePoint fixes — but nobody in our coverage has checked them. The weakest link is also the headline: the one exploited August CVE is never named, so the claim that carries the whole 'volume without exploitation' argument is the one a reader cannot verify at all.
Shipping is well documented; installing is not
The release side of this story is dense and dated: Microsoft's August cycle, Chrome 152 with an exploited flaw of its own, Adobe's seven updates on August 25, Mozilla's September 1 sweep, three CVSS 10.0 issues Microsoft closed inside its own cloud, and KEV additions over the past two months. What is entirely absent is the other half of a patch story — how much of any of this is actually deployed. No patch-latency figure, no share of SharePoint servers still missing July, no maintenance-window length. The column argues exposure comes from cycle lag and then offers no measurement of the lag.
'Patch Apocalypse' framing, deflated in its own second sentence
The column brands the moment — record volume, third month of a 'Patch Apocalypse', the whole portfolio possibly updated again — and then immediately reports that one CVE out of 398 was confirmed exploited and that the AI-driven attack wave has been slow to appear. That self-correction is unusual and it keeps the overstatement modest: the alarm lives in the count, the reassurance in the exploitation data, and both are in the same paragraph. Our own framing pushes further in the deflating direction by putting exposure on cycle lag rather than on volume. What remains overstated is scale as a proxy for danger, plus a forecast of continued growth offered with no series behind it.
A vendor's gap becomes a vendor's product
The single outside voice is Microsoft's corporate vice president for Azure Networking, whose argument — patch windows have collapsed, so treat the network as a control plane — resolves neatly into his own product area, and the column endorses it as dovetailing with risk-driven remediation. Around that sits a recurring franchise with its own branding: a named phenomenon now in its third month, a cross-reference to last month's methodology, and a week-ahead watch list that guarantees next month's instalment. None of that makes the facts wrong, but the one disclosure a patch-forecast column most needs — who the author works for — is absent from what we have.
Solid on the calendar, thin on the threat
Split the story in two and the confidence splits with it. The lifecycle dates, CVE identifiers, CVSS values and vendor release timings are the sort of detail that would be trivially disproved if wrong, and they hold together. The parts that would actually change an operator's week — a chain being exploited right now, an unpatched Defender flaw with public proof-of-concept code, a September fix that had not shipped when this was written — stand on a single practitioner's assertion with no attribution and no telemetry. One publisher, no cross-checking, and the most actionable claims are the least supported.