August, 2026: Patch Tuesday - Three Zero Days this Month

Welcome to my August 2026 Patch Tuesday newsletter. It's been what is becoming a normal month from Microsoft with the amount of patches released. Today, MS released 399 updates and another 61 since last month's Patch Tuesday. So, in total we have 460 updates in the chart below.

This month we have three zero-days to tell you about:

  • CVE-2026-62832 - This elevation of privilege vulnerability affects most flavors of Microsoft's OS's. It is currently being exploited but not publicly disclosed. An attacker who is authenticated and has credentials for another local account could run specially crafted code to load another user's registry hive. If successful, the attacker could gain access to the user's data and gain ADMIN privileges. It is rated as "Important" by Microsoft.
  • CVE-2026-72971 - This tampering vulnerability affects only Windows 11 26H1. An issue with the unionfs.sys driver file could allow an attacker to tamper locally.
  • CVE-2026-68820 - This elevation of privilege vulnerability affects most Microsoft OS's currently supported. An attacker who is successful could gain SYSTEM privileges. Microsoft rates this as "Important" as well. The attack complexity is high since it requires a user to win a race condition.

Besides these we have 77 "Critical" rated CVE's being pushed out for the month. You will want to peruse the chart below to see if your environment contains any of the affected applications and the vulnerable versions.

So, without further ado, here’s the chart of MS patches that affect Windows platforms in the past month.

Patch data provided by:

LOGbinder.com

Technology

Products Affected

Severity

Reference

Workaround/ Exploited / Publicly Disclosed

Vulnerability Info

Windows

Windows 10, 11

Server 2012, 2012 R2, 2016, 2019, 2022, 2025 including Server Core Installations

Remote Desktop Web Client

Windows App Client for Windows Desktop

Windows Admin Center

Critical

CVE-2026-42976
CVE-2026-49179
CVE-2026-50472
CVE-2026-54113
CVE-2026-54984
CVE-2026-56171
CVE-2026-56174
CVE-2026-56179
CVE-2026-58598
CVE-2026-58643
CVE-2026-59122
CVE-2026-59124
CVE-2026-59125
CVE-2026-59126
CVE-2026-59127
CVE-2026-59128
CVE-2026-59130
CVE-2026-59131
CVE-2026-59132
CVE-2026-59133
CVE-2026-59134
CVE-2026-59135
CVE-2026-59136
CVE-2026-59137
CVE-2026-59138
CVE-2026-61345
CVE-2026-61346
CVE-2026-61347
CVE-2026-61348
CVE-2026-61349
CVE-2026-61350
CVE-2026-61352
CVE-2026-61353
CVE-2026-61355
CVE-2026-61356
CVE-2026-61357
CVE-2026-61358
CVE-2026-61359
CVE-2026-61360
CVE-2026-61361
CVE-2026-61363
CVE-2026-61364
CVE-2026-61365
CVE-2026-61366
CVE-2026-61367
CVE-2026-61368
CVE-2026-61918
CVE-2026-61920
CVE-2026-61921
CVE-2026-61923
CVE-2026-61924
CVE-2026-61925
CVE-2026-61926
CVE-2026-61927
CVE-2026-61928
CVE-2026-61929
CVE-2026-61930
CVE-2026-61932
CVE-2026-61933
CVE-2026-61934
CVE-2026-61936
CVE-2026-61937
CVE-2026-61938
CVE-2026-61939
CVE-2026-62688
CVE-2026-62690
CVE-2026-62692
CVE-2026-62693
CVE-2026-62695
CVE-2026-62696
CVE-2026-62698
CVE-2026-62699
CVE-2026-62700
CVE-2026-62701
CVE-2026-62702
CVE-2026-62703
CVE-2026-62705
CVE-2026-62707
CVE-2026-62708
CVE-2026-62709
CVE-2026-62710
CVE-2026-62711
CVE-2026-62712
CVE-2026-62713
CVE-2026-62714
CVE-2026-62715
CVE-2026-62716
CVE-2026-62717
CVE-2026-62718
CVE-2026-62719
CVE-2026-62720
CVE-2026-62721
CVE-2026-62722
CVE-2026-62723
CVE-2026-62724
CVE-2026-62725
CVE-2026-62726
CVE-2026-62728
CVE-2026-62729
CVE-2026-62730
CVE-2026-62732
CVE-2026-62733
CVE-2026-62734
CVE-2026-62735
CVE-2026-62736
CVE-2026-62737
CVE-2026-62738
CVE-2026-62739
CVE-2026-62740
CVE-2026-62741
CVE-2026-62742
CVE-2026-62743
CVE-2026-62745
CVE-2026-62746
CVE-2026-62747
CVE-2026-62748
CVE-2026-62749
CVE-2026-62750
CVE-2026-62751
CVE-2026-62752
CVE-2026-62753
CVE-2026-62754
CVE-2026-62755
CVE-2026-62757
CVE-2026-62758
CVE-2026-62761
CVE-2026-62766
CVE-2026-62768
CVE-2026-62769
CVE-2026-62770
CVE-2026-62771
CVE-2026-62772
CVE-2026-62773
CVE-2026-62774
CVE-2026-62775
CVE-2026-62776
CVE-2026-62777
CVE-2026-62778
CVE-2026-62779
CVE-2026-62780
CVE-2026-62781
CVE-2026-62782
CVE-2026-62783
CVE-2026-62784
CVE-2026-62785
CVE-2026-62786
CVE-2026-62787
CVE-2026-62788
CVE-2026-62790
CVE-2026-62792
CVE-2026-62793
CVE-2026-62795
CVE-2026-62796
CVE-2026-62797
CVE-2026-62798
CVE-2026-62799
CVE-2026-62800
CVE-2026-62803
CVE-2026-62807
CVE-2026-62811
CVE-2026-62812
CVE-2026-62814
CVE-2026-62815
CVE-2026-62816
CVE-2026-62817
CVE-2026-62818
CVE-2026-62819
CVE-2026-62820
CVE-2026-62822
CVE-2026-62823
CVE-2026-62824
CVE-2026-62832*
CVE-2026-62876
CVE-2026-62877
CVE-2026-62878
CVE-2026-62880
CVE-2026-62881
CVE-2026-62883
CVE-2026-62885
CVE-2026-62887
CVE-2026-62888
CVE-2026-62889
CVE-2026-62890
CVE-2026-62892
CVE-2026-62893
CVE-2026-62894
CVE-2026-62908
CVE-2026-65662
CVE-2026-65671
CVE-2026-65672
CVE-2026-65678
CVE-2026-65679
CVE-2026-65681
CVE-2026-65773
CVE-2026-65774
CVE-2026-65775
CVE-2026-65776
CVE-2026-65777
CVE-2026-65778
CVE-2026-65779
CVE-2026-65780
CVE-2026-65781
CVE-2026-65782
CVE-2026-65783
CVE-2026-65784
CVE-2026-65785
CVE-2026-65786
CVE-2026-65787
CVE-2026-65788
CVE-2026-65789
CVE-2026-65790
CVE-2026-65791
CVE-2026-65794
CVE-2026-65795
CVE-2026-65796
CVE-2026-65797
CVE-2026-65798
CVE-2026-65799
CVE-2026-65814
CVE-2026-66799
CVE-2026-66802
CVE-2026-66804
CVE-2026-68819
CVE-2026-68820**
CVE-2026-70304
CVE-2026-70307
CVE-2026-70330
CVE-2026-70344
CVE-2026-70345
CVE-2026-70346
CVE-2026-70347
CVE-2026-70348
CVE-2026-71331
CVE-2026-72971*

Workaround: No
Exploited: Yes**
Public: Yes*

Denial of Service

Elevation of Privilege

Information Disclosure

Remote Code Execution

Security Feature Bypass

Spoofing

Tampering

Exchange

Server 2016 CU23

Server 2019 CU14, CU15

Server Subscription Edition RTM

Exchange Online

Critical

CVE-2026-56191
CVE-2026-62910
CVE-2026-62911
CVE-2026-62912
CVE-2026-62913
CVE-2026-62914
CVE-2026-62915
CVE-2026-65813

Workaround: No
Exploited: No
Public: No

Denial of Service

Elevation of Privilege

Remote Code Execution

Security Feature Bypass

Spoofing

Tampering

SQL Server

Power BI Report Server

Important

CVE-2026-65811

Workaround: No
Exploited: No
Public: No

Remote Code Execution

Edge

Edge (Chromium-based)

Edge for Android

Surface Management Services

Critical

CVE-2026-54120
CVE-2026-57978
CVE-2026-57980
CVE-2026-57989
CVE-2026-57990
CVE-2026-62828
CVE-2026-65802
CVE-2026-65804
CVE-2026-66310
CVE-2026-66311
CVE-2026-66312
CVE-2026-66313
CVE-2026-66314
CVE-2026-66315
CVE-2026-66316
CVE-2026-66317
CVE-2026-66318
CVE-2026-66321
CVE-2026-66322
CVE-2026-66325
CVE-2026-66326
CVE-2026-70339

Workaround: No
Exploited: No
Public: No

Information Disclosure

Remote Code Execution

Spoofing

Tampering

Office

365 Apps for Enterprise

Access/Excel/Word/Outlook/
PowerPoint 2016

Office 2016, 2019

LTSC 2021, 2024 including for Mac

Office 365 for Mac

Teams (including for Android and iOS)

OneDrive for MacOS

Critical

CVE-2026-58651
CVE-2026-62842
CVE-2026-62870
CVE-2026-62882
CVE-2026-62896
CVE-2026-62918
CVE-2026-63513
CVE-2026-63515
CVE-2026-63517
CVE-2026-63518
CVE-2026-63519
CVE-2026-63521
CVE-2026-63524
CVE-2026-63525
CVE-2026-63526
CVE-2026-63527
CVE-2026-63528
CVE-2026-63529
CVE-2026-63530
CVE-2026-63531
CVE-2026-63532
CVE-2026-63533
CVE-2026-64898
CVE-2026-64899
CVE-2026-64903
CVE-2026-64904
CVE-2026-64905
CVE-2026-64906
CVE-2026-64907
CVE-2026-64908
CVE-2026-64909
CVE-2026-64910
CVE-2026-64911
CVE-2026-64912
CVE-2026-64914
CVE-2026-64915
CVE-2026-64917
CVE-2026-64919
CVE-2026-64920
CVE-2026-65656
CVE-2026-65657
CVE-2026-65661
CVE-2026-65664
CVE-2026-65667
CVE-2026-65680
CVE-2026-65767
CVE-2026-65768
CVE-2026-65769
CVE-2026-65807
CVE-2026-66806
CVE-2026-66807
CVE-2026-66809
CVE-2026-66810
CVE-2026-68792
CVE-2026-68793
CVE-2026-68794
CVE-2026-68795
CVE-2026-68796
CVE-2026-68797
CVE-2026-68798
CVE-2026-68799
CVE-2026-68800
CVE-2026-68801
CVE-2026-68802
CVE-2026-68803
CVE-2026-68804
CVE-2026-68805
CVE-2026-68806
CVE-2026-68807
CVE-2026-68808
CVE-2026-68809
CVE-2026-68810
CVE-2026-68811
CVE-2026-68812
CVE-2026-68813
CVE-2026-68814
CVE-2026-68815
CVE-2026-68816
CVE-2026-68817
CVE-2026-70130
CVE-2026-70310
CVE-2026-70311
CVE-2026-70312
CVE-2026-70313
CVE-2026-70314
CVE-2026-70315
CVE-2026-70316
CVE-2026-70317
CVE-2026-70318
CVE-2026-70319
CVE-2026-70320
CVE-2026-70322
CVE-2026-70323
CVE-2026-70325
CVE-2026-70327
CVE-2026-70328
CVE-2026-70329

Workaround: No
Exploited: No

Public: No

Elevation of Privilege

Information Disclosure

Remote Code Execution

Spoofing

SharePoint

Enterprise Server 2016

Server 2019

Server Subscription Edition

SharePoint Online

Critical

CVE-2026-57105
CVE-2026-58639
CVE-2026-62826
CVE-2026-62827
CVE-2026-62829
CVE-2026-62837
CVE-2026-62839
CVE-2026-62917
CVE-2026-63512
CVE-2026-63514
CVE-2026-63516
CVE-2026-63520
CVE-2026-64897
CVE-2026-64900
CVE-2026-64901
CVE-2026-64902
CVE-2026-64916
CVE-2026-64921
CVE-2026-64922
CVE-2026-65658
CVE-2026-65660
CVE-2026-65663
CVE-2026-65665
CVE-2026-66805
CVE-2026-66808
CVE-2026-70306
CVE-2026-70321
CVE-2026-70324
CVE-2026-70326
CVE-2026-70332
CVE-2026-70355

Workaround: No
Exploited: No
Public: No
Elevation of Privilege

Information Disclosure

Remote Code Execution

Spoofing

Tampering

Azure

Application Insights Profiler

Azure Active Directory

AI Service

API Management (APIM)

App Service for Linux

Confidential Ledger

Cosmos DB

CycleCloud 8.9.1/8.9.2

DNS

Key Vault

Kubernetes Service

Logic Apps

Monitor Agent Linux Extension

Portal

Red Hat OpenShift (ARO)

Service Bus

SQL Database

SQL Managed Instance

SRE Agent

365 Admin Center

Microsoft Account

MS Entra Connect

MS Entra ID

MS Entra Provisioning Service

MS Graph

MS Purview Data Governance

MS Purview eDiscovery

Critical

CVE-2026-35425
CVE-2026-47299
CVE-2026-49159
CVE-2026-49163
CVE-2026-50481
CVE-2026-50515
CVE-2026-50516
CVE-2026-56160
CVE-2026-56161
CVE-2026-56162
CVE-2026-56163
CVE-2026-56165
CVE-2026-56167
CVE-2026-57106
CVE-2026-58275
CVE-2026-58630
CVE-2026-59115
CVE-2026-62825
CVE-2026-62830
CVE-2026-62835
CVE-2026-62836
CVE-2026-62869
CVE-2026-62873
CVE-2026-63522
CVE-2026-65668
CVE-2026-65673
CVE-2026-65806
CVE-2026-66803
CVE-2026-68823
CVE-2026-70340

Workaround: No
Exploited: No

Public: No

Elevation of Privilege

Information Disclosure

Remote Code Execution

Spoofing

Developer Tools

.NET 8, 9, 10 installed on Linux, MacOS and Windows

.NET Framework 4.6.2, 4.7, 4.7.1, 4.7.2, 4.8, 4.8.1

Visual Studio
2022 17.14,
2026 18.8

Visual Studio Code

Visual Studio Code CoPilot Chat Extension

PowerShell 7.4, 7.5, 7.6

Python extension for Visual Studio Code

Important

CVE-2026-47285
CVE-2026-54981
CVE-2026-58612
CVE-2026-58641
CVE-2026-58650
CVE-2026-59113
CVE-2026-59119
CVE-2026-62871
CVE-2026-62872
CVE-2026-62886
CVE-2026-62897
CVE-2026-62898
CVE-2026-62899
CVE-2026-62900
CVE-2026-62901
CVE-2026-62902
CVE-2026-62909
CVE-2026-65675
CVE-2026-65810
CVE-2026-69278
CVE-2026-69306
CVE-2026-69320
CVE-2026-70335
CVE-2026-70336
CVE-2026-70337
CVE-2026-70338
CVE-2026-70354

Workaround: No
Exploited: No
Public: No

Denial of Service

Elevation of Privilege

Information Disclosure

Remote Code Execution

Security Feature Bypass

Dynamics

CoPilot Cowork

365 (on-premises) v9.1

365 Business Central 2024 Release Wave 2, 2025 Release Wave 1 & 2, 2026 Release Wave 1

Critical

CVE-2026-40375
CVE-2026-59118
CVE-2026-65815
CVE-2026-66301

Workaround: No
Exploited: No
Public: No

Elevation of Privilege

Information Disclosure

Remote Code Execution

Device

MS Planetary Computer Pro (GeoCatalog)

Critical

CVE-2026-63508

Workaround: No
Exploited: No
Public: No

Elevation of Privilege

Apps

Installer

365 CoPilot

Windows Terminal App

Critical

CVE-2026-50517
CVE-2026-59117
CVE-2026-68821

Workaround: No
Exploited: No
Public: No

Elevation of Privilege

Remote Code Execution

System Center

Defender for EndPoint for Mac

Important

CVE-2026-54123

Workaround: No
Exploited: No
Public: No

Information Disclosure

Open Source Software

Azure Storage Explorer

Important

CVE-2026-57104

Workaround: No
Exploited: No

Public: No

Elevation of Privilege