August 14, 2026, marked the end of one of the most intense months in the history of corporate cybersecurity. As part of the traditional "Patch Tuesday" update cycle, Microsoft released a massive patch package addressing over 400 vulnerabilities in its products. Among them were 42 critical flaws allowing attackers to remotely execute malicious code. Experts paid particular attention to the presence of three zero-day vulnerabilities, one of which was already being actively exploited in the wild.
Active Exploitation of Lazarus Vulnerability
The central event of the August update was vulnerability CVE-2026-68820, discovered in the Windows Ancillary Function Driver for WinSock. This "Use after free" error allows a local authorized attacker to trigger a race condition and gain SYSTEM privileges. According to Check Point, this loophole was already used by the North Korean hacking group Lazarus to deploy a new version of the FudModule rootkit in kernel mode. This confirms that the threat is not theoretical but real and has already caused damage to some organizations.
Two Additional Zero-Day Vulnerabilities
In addition to CVE-2026-68820, Microsoft patched two other critical zero-day vulnerabilities. CVE-2026-62832 in the Windows User Profile Service allows a local user to load another account's registry hive and gain administrator privileges. This bug matches the LegacyHive vulnerability previously discovered by researcher Nightmare Eclipse. The second vulnerability, CVE-2026-72971, affects the Windows Container Isolation Driver (unionfs.sys) and allows local privilege escalation due to incorrect handling of references before accessing files.
Conflicting Data
While most sources agree that Microsoft patched around 400 vulnerabilities, the exact figures vary. According to SecurityWeek, 421 CVEs were fixed, whereas ITWire reports 398 vulnerabilities. The discrepancy may be due to some sources counting only updates released on Patch Tuesday itself, while others include previously fixed bugs in Mariner, Microsoft Teams, Azure, Entra, Office, and Power Apps. This creates uncertainty in the overall statistics but does not change the essence: the scale of the updates was unprecedented.
Updates from Other Tech Giants
Microsoft was not the only company to release critical updates in August 2026. Adobe patched vulnerabilities in Coldfusion, Commerce, Lightroom Classic, Content Credentials SDK, and Campaign Classic. Cisco addressed flaws in Catalyst SD-WAN, IOS, IOS XE, and ClamAV. Metabase patched a critical SQL injection vulnerability used for data theft. N-able fixed an authentication bypass (CVE-2026-18577) in N-central servers. SAP released a fix for SAP Commerce Cloud with a criticality rating of 10.0 due to improper authorization. TP-Link addressed 15 vulnerabilities in the ZTP mechanism of Omada network devices. VMware fixed an authentication bypass and remote code execution possibility in VMware Avi Load Balancer.
Recommendations for Organizations
Experts strongly recommend that all organizations immediately apply Microsoft's August updates, especially if they use Windows in a production environment. Given the active exploitation of the Lazarus vulnerability, delaying patching could lead to serious incidents. It is also important to check for updates from other vendors, as many of them affected critical infrastructure components.