---
title: "August 2026 Patch Tuesday: Microsoft Patches 400 Vulnerabilities, Including Lazarus Attack"
description: "🚨 Microsoft patched 400+ vulnerabilities in August 2026, including 3 zero-days! One was already exploited by the Lazarus group. Update urgently! #cybersecurity #microsoft #patchtuesday"
date: 2026-08-14T12:22:00.000Z
lang: en
url: https://xab.info/en/posts/august-2026-patch-tuesday-microsoft-400-vulnerabilities-lazarus-en
tags: [microsoft, cybersecurity, patch-tuesday, zero-day, lazarus, cve, windows]
publisher: "XAB.info"
---

# August 2026 Patch Tuesday: Microsoft Patches 400 Vulnerabilities, Including Lazarus Attack

![Microsoft logo on the facade of a modern building, illustrating the theme of August Patch Tuesday 2026 and vulnerability fixes](https://xab.info/media/2026/08/14/august-2026-patch-tuesday-microsoft-400-vulnerabilities-lazarus/august-2026-patch-tuesday-microsoft-400-vulnerabilities-lazarus-1.webp)

## 🎯 Key Points

- Microsoft patched over 400 vulnerabilities, including 42 critical ones.
- Three zero-day vulnerabilities, one of which was actively exploited by Lazarus.
- CVE-2026-68820 allows gaining SYSTEM privileges via race condition.
- Other companies (Adobe, Cisco, VMware) also released critical updates.

August 14, 2026, marked the end of one of the most intense months in the history of corporate cybersecurity. As part of the traditional "Patch Tuesday" update cycle, Microsoft released a massive patch package addressing over 400 vulnerabilities in its products. Among them were 42 critical flaws allowing attackers to remotely execute malicious code. Experts paid particular attention to the presence of three zero-day vulnerabilities, one of which was already being actively exploited in the wild.

### Active Exploitation of Lazarus Vulnerability

The central event of the August update was vulnerability CVE-2026-68820, discovered in the Windows Ancillary Function Driver for WinSock. This "Use after free" error allows a local authorized attacker to trigger a race condition and gain SYSTEM privileges. According to Check Point, this loophole was already used by the North Korean hacking group Lazarus to deploy a new version of the FudModule rootkit in kernel mode. This confirms that the threat is not theoretical but real and has already caused damage to some organizations.

### Two Additional Zero-Day Vulnerabilities

In addition to CVE-2026-68820, Microsoft patched two other critical zero-day vulnerabilities. CVE-2026-62832 in the Windows User Profile Service allows a local user to load another account's registry hive and gain administrator privileges. This bug matches the LegacyHive vulnerability previously discovered by researcher Nightmare Eclipse. The second vulnerability, CVE-2026-72971, affects the Windows Container Isolation Driver (unionfs.sys) and allows local privilege escalation due to incorrect handling of references before accessing files.

### Conflicting Data

While most sources agree that Microsoft patched around 400 vulnerabilities, the exact figures vary. According to SecurityWeek, 421 CVEs were fixed, whereas ITWire reports 398 vulnerabilities. The discrepancy may be due to some sources counting only updates released on Patch Tuesday itself, while others include previously fixed bugs in Mariner, Microsoft Teams, Azure, Entra, Office, and Power Apps. This creates uncertainty in the overall statistics but does not change the essence: the scale of the updates was unprecedented.

### Updates from Other Tech Giants

Microsoft was not the only company to release critical updates in August 2026. Adobe patched vulnerabilities in Coldfusion, Commerce, Lightroom Classic, Content Credentials SDK, and Campaign Classic. Cisco addressed flaws in Catalyst SD-WAN, IOS, IOS XE, and ClamAV. Metabase patched a critical SQL injection vulnerability used for data theft. N-able fixed an authentication bypass (CVE-2026-18577) in N-central servers. SAP released a fix for SAP Commerce Cloud with a criticality rating of 10.0 due to improper authorization. TP-Link addressed 15 vulnerabilities in the ZTP mechanism of Omada network devices. VMware fixed an authentication bypass and remote code execution possibility in VMware Avi Load Balancer.

### Recommendations for Organizations

Experts strongly recommend that all organizations immediately apply Microsoft's August updates, especially if they use Windows in a production environment. Given the active exploitation of the Lazarus vulnerability, delaying patching could lead to serious incidents. It is also important to check for updates from other vendors, as many of them affected critical infrastructure components.

## 🔍 Fact-Check Verification

- [August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day](https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/) - Подтверждает 421 CVE и активную эксплуатацию одной уязвимости.
- [Microsoft's August Patch Tuesday: 398 flaws, 3 zero-days, and one North Korea got to first](https://itwire.com/business-it-news/security/microsofts-august-patch-tuesday-398-flaws-3-zero-days-and-one-north-korea-got-to-first) - Указывает на 398 уязвимостей и подтверждает участие Lazarus.
- [Microsoft fixes around 400 flaws in August 2026 Patch Tuesday](https://www.msn.com/en-xl/news/other/microsoft-fixes-around-400-flaws-in-august-2026-patch-tuesday/ar-AA29THEc) - Общее подтверждение масштаба обновлений.
- [Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack](https://www.techrepublic.com/article/news-microsoft-august-2026-patch-tuesday/) - Подтверждает наличие эксплуатируемой уязвимости.

## ❓ FAQ

### Q: How many vulnerabilities did Microsoft patch in August 2026?
**A:** Around 400, the exact number varies from 398 to 421 depending on the source.

### Q: Which zero-day vulnerabilities were fixed?
**A:** CVE-2026-68820, CVE-2026-62832, and CVE-2026-72971.

### Q: Who exploited vulnerability CVE-2026-68820?
**A:** The North Korean group Lazarus.

### Q: Which other companies released updates in August?
**A:** Adobe, Cisco, Metabase, N-able, SAP, TP-Link, VMware.