Skip to main content

Microsoft Releases Aug 2026 Security Updates

Scheduled updates for Microsoft products address 421 Microsoft vulnerabilities, including 3 zero-day vulnerabilities

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Scheduled updates for Microsoft products address 421 Microsoft vulnerabilities, including 3 zero-day vulnerabilities


Affected platforms

The following platforms are known to be affected:

The following platforms are also known to be affected:

Multiple other Microsoft platforms. Please see Microsoft's Aug 2026 Security Updates guide for full details. 

Threat details

Three zero-day vulnerabilities identified

Microsoft states that exploitation of CVE-2026-68820 has been detected. Two other vulnerabilities, CVE-2026-62832 and CVE-2026-72971, have been reported as publicly disclosed.

NHS England National CSOC assess that future exploitation is highly likely.


Introduction

Microsoft has released security updates to address 421 vulnerabilities in Microsoft products, including the 3 zero-day vulnerabilities highlighted below.

  • CVE-2026-68820 - Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability with a CVSSv3 base score of 7.0, arising from a 'Use After Free' weakness. This vulnerability has been reported as actively exploited.
  • CVE-2026-62832 - Windows User Profile Service elevation of privilege vulnerability with a CVSSv3 base score of 7.8, arising from an 'improper link resolution before file access (link following)' weakness.
  • CVE-2026-72971 - Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability with a CVSSv3 base score of 5.5, arising from an 'improper link resolution before file access (link following)' weakness.

Chained vulnerabilities in Microsoft SharePoint Server

Cyber Alert CC-4829 describes a potential exploitation chain of CVE-2026-55040 and CVE-2026-63520 that could lead to unauthenticated remote code execution against a vulnerable SharePoint server. 

SharePoint Server 2016 and 2019 are no longer supported

As of 14 July 2026, Microsoft ended their extended support for SharePoint Server 2016 and SharePoint Server 2019. These products are now unsupported by Microsoft. Organisations are strongly encouraged to move to a supported version.


Remediation advice

Affected organisations are encouraged to review Microsoft's August 2026 Security Updates and apply the relevant updates as soon as possible.



Last edited: 12 August 2026 12:55 pm