Particle.news
Download on the App Store

Microsoft Fixes Nearly 400 Flaws in August Patch Day

Administrators must install the new updates because attackers are actively exploiting a Winsock zero-day.

Overview

  • Microsoft released the August Patch Day updates on August 11, closing 398 newly reported vulnerabilities with 42 rated critical.
  • At least one zero-day, CVE-2026-68820 in the afd.sys Winsock driver, is being actively exploited and can let a local, authenticated attacker elevate to system privileges.
  • The fixes extend beyond Windows to Office, Exchange Server, Teams, Hyper-V, Defender and Azure, and a separate Edge update on August 10 patched 41 Chromium bugs that are not included in the 398 count.
  • Some Azure issues were remediated server-side by Microsoft so no admin action is required, and a critical Exchange Server elevation-of-privilege bug (CVE-2026-62911) was patched after its exploitability was shown at Pwn2Own in May.
  • A circulating proof-of-concept called ShieldBreak claims to bypass a recent Defender fix for RoguePlanet but remains unverified, so security teams are urged to apply the published patches and monitor proof-of-concept disclosures.