Cyber Resilience
← All news
Corroborated

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Our takeMicrosoft's August 2026 Patch Tuesday fixes 421 CVEs, including one exploited zero-day in afd.sys that reaches SYSTEM and two other zero-days. Patch today.
Sources (2)
What this means for you — Security leader:Apply the August 2026 Patch Tuesday updates across Windows, Office, Edge, and related components. Prioritize the actively exploited use-after-free in afd.sys (CVE-2026-XXXX) and the two disclosed zero-days.
What this means for you — Lean IT orgs:Install Microsoft's August updates as soon as you can. They fix over 400 flaws including one already being exploited in the wild and two zero-days; most smaller teams should just run Windows Update or let your managed provider handle it.
What this means for you — MSP:Deploy the August 2026 Patch Tuesday bundle to all managed Windows endpoints and servers. One kernel use-after-free is already exploited for SYSTEM access and two zero-days are public; prioritize these across client estates.
What this means for you — Researcher:Microsoft's August 2026 Patch Tuesday addresses 421 CVEs including one exploited zero-day (afd.sys use-after-free) and two additional public zero-days.