Skip to main content
LiMP VPN
All news

Microsoft Closes 400 Windows Vulnerabilities in August 2026

Microsoft Closes 400 Windows Vulnerabilities in August 2026

In short: On August 12, 2026, Microsoft released its monthly Patch Tuesday update, fixing a record 400 vulnerabilities in Windows and other products — including three zero-days, one of which had already been actively exploited by a hacker group in targeted attacks. If your Windows device is set to auto-update, the critical step is already done. If not, open Windows Update now and install the security patches.

400 vulnerabilities in a single update — why it matters

August 2026's Patch Tuesday is the largest Microsoft security release on record by patch count. Of the 400 fixed vulnerabilities, 42 are rated Critical — the highest severity level in Microsoft's classification. Researchers from Positive Technologies (SecurityLab.ru) broke down the categories:

  • 110 vulnerabilities enable remote code execution (RCE) — an attacker can run malicious code on your machine without physical access.
  • 176 vulnerabilities allow privilege escalation (EoP) — gaining administrator or SYSTEM-level rights from a restricted account.
  • 86 vulnerabilities lead to information disclosure — exposing confidential data without the user's knowledge.

The high patch count does not mean Windows has become less secure. It reflects a deliberate strategy: Microsoft has accelerated its code review cycles and started using AI-assisted vulnerability scanning. The faster flaws are found, the faster they get closed — and the larger the monthly tally.

Three zero-days: what happened before the patch

A zero-day is a vulnerability that was already being exploited before Microsoft became aware of it and issued a fix. This month, there are three.

CVE-2026-68820 (CVSS 7.0) — a use-after-free flaw in the Windows AFD.sys network driver (the Winsock subsystem). It allows an attacker to escalate privileges to SYSTEM level, effectively taking full control of the operating system. According to SecurityLab.ru, this vulnerability was already used in targeted attacks against defense and aerospace professionals before the patch was released. It is now fixed.

CVE-2026-62832 (CVSS 7.8) — a flaw in the Windows User Profile Service that allows unauthorized access to the registry and potential escalation to administrator rights. No advanced technical skills are required to exploit it, which lowers the barrier for mass exploitation campaigns.

CVE-2026-72971 (CVSS 5.5) — a bug in the unionfs.sys driver that handles file system isolation in Windows containers. It can break container boundaries — relevant for enterprise environments and developers working with containerized applications.

What this means for everyday Windows users

Most of the 400 vulnerabilities require either physical access to a device or a malicious file to be run first. But RCE vulnerabilities and zero-days can fire with far less user interaction — sometimes just being connected to a compromised network is enough.

Privilege escalation vulnerabilities are particularly dangerous in combination with other attacks: a piece of malware delivered via phishing can use an EoP flaw to gain administrator rights and from there do virtually anything — encrypting files, stealing passwords, or installing spyware that persists across reboots.

Public Wi-Fi networks in cafés, hotels, and airports are high-risk environments where an attacker on the same local network can exploit certain network-level vulnerabilities. The LiMP VPN app encrypts your traffic and hides your activity from other users on the network. That said, VPN protection and OS updates are separate layers: VPN operates at the network level, while these vulnerabilities live inside the operating system itself. You need both. Read more about layered protection in our security blog.

Five steps to protect yourself now

  1. Install the August update immediately. Open Settings → Windows Update → Check for updates. Install all available security patches. If prompted to restart — do it without delay.
  2. Enable automatic updates. Make sure auto-updates are on in Windows Update settings so future Patch Tuesdays reach you automatically.
  3. Update Microsoft Office and Edge separately. Some August patches cover Office apps and the Edge browser, which update independently from the OS.
  4. Secure your accounts. EoP flaws are most dangerous when an attacker already has a foothold. Use strong, unique passwords and enable two-factor authentication on your Microsoft account.
  5. Use a VPN on public networks. Cafés, hotels, and airports are high-risk environments. A VPN encrypts your traffic and reduces exposure to several network-level attack vectors.

Sources

Microsoft Closes 400 Windows Vulnerabilities in August 2026