What happened
Microsoft shipped its August 2026 Patch Tuesday updates on August 11, fixing roughly 400 vulnerabilities — trackers count between 398 and 421 depending on what they include, with one tally putting 62 in the critical category. Three of the flaws qualify as zero-days. The one that matters most is CVE-2026-68820, a use-after-free bug in afd.sys, the Windows Ancillary Function Driver for WinSock. It is being exploited in the wild and lets an attacker who already has a foothold on a machine elevate to SYSTEM, the highest level of Windows privilege. Two other flaws were publicly known before fixes shipped. The release also covers Microsoft Exchange Server, Hyper-V, NTFS, HTTP.sys, Dynamics 365 Business Central, and developer tools including GitHub Copilot and Visual Studio Code. Adobe published its own batch of security updates the same day.
Why it matters for your business
Privilege-escalation bugs like CVE-2026-68820 are the second half of most real intrusions: a phishing email or malicious download gets an attacker in the door, and a flaw like this hands them the keys to the whole machine. Patching it removes a step attackers are actively using right now. For small businesses, the monthly rhythm matters more than any single CVE — organizations that apply updates within days, not months, sidestep the majority of opportunistic attacks.
What to do about it
- Apply the August updates this week and confirm machines actually rebooted to complete installation
- Prioritize anything internet-facing and any server running Exchange
- If an IT provider handles patching, ask them to confirm CVE-2026-68820 is covered across your fleet
- Check the laptops that never come to the office — remote and personal-use machines are the ones that slip through
