Microsoft released its August 2026 Patch Tuesday security updates yesterday (12 August), addressing
421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities
. For UK SMEs, this represents another substantial monthly security challenge requiring systematic patch deployment across all Microsoft infrastructure—particularly as
three zero-day vulnerabilities
demand immediate attention.
While this month’s release is smaller than July’s record-breaking 569 vulnerabilities, the volume remains significantly elevated and includes one actively exploited flaw that attackers are already using in the wild.
Microsoft August 2026 Patch Tuesday: The Critical Zero-Day Vulnerabilities
This month’s patches include fixes for one exploited zero-day vulnerability, three disclosed zero-day vulnerabilities, and 62 Critical vulnerabilities
. The most urgent flaw requires immediate attention from all Windows administrators:
- CVE-2026-68820 (Windows Ancillary Function Driver for WinSock):
This zero-day bug allows a locally authenticated attacker to gain SYSTEM-level access on affected systems
. This elevation of privilege vulnerability is being actively exploited and must be patched within 24–48 hours. - CVE-2026-62832 (Windows User Profile Service):
This is another elevation-of-privilege vulnerability that affects the Windows User Profile Service
. Though not yet exploited, this flaw was publicly disclosed before Microsoft’s patch release, increasing exploitation risk. - CVE-2026-72971 (Windows Container Isolation):
CVE-2026-72971 affects the unionfs.sys driver used by Windows Container Isolation. Microsoft classifies it as a tampering vulnerability
, with
it had already been publicly disclosed when the August update was released
.
Scope of the August 2026 Security Release
Of these, 236 vulnerabilities affect Windows, while 98 each affect Office and Office 2016
. The update also includes fixes across Exchange Server, SharePoint, Azure services, and developer tools.
By vulnerability type,
180 of the vulnerabilities in Microsoft’s August 2026 update were elevation of privilege (EoP) issues that give attackers the ability to gain full SYSTEM level privileges on affected devices
. Remote code execution flaws—which allow attackers to run malicious code remotely—account for another 109 vulnerabilities.
Kent businesses using Microsoft 365 should note that
the number of flaws does not include some flaws in Mariner, Microsoft Teams, Microsoft Azure, Microsoft Entra, Microsoft Office, and Power Apps that were fixed by Microsoft earlier this month
, so additional updates may already be pending deployment.
What Kent SMEs Must Do This Week
Deploy Critical Patches Within 48 Hours
The actively exploited CVE-2026-68820 must be your immediate priority. Even though this is an elevation of privilege flaw requiring local access rather than a remote code execution vulnerability,
timely patching remains critical for reducing exposure and strengthening enterprise security
.
Deploy these patches in order of priority:
- CVE-2026-68820 (Windows Ancillary Function Driver)—deploy within 24–48 hours
- CVE-2026-62832 (Windows User Profile Service)—deploy within 48–72 hours
- CVE-2026-71331 (Azure Attestation/Device Health Attestation)—critical RCE flaw for organisations using these services
- Remaining critical-severity vulnerabilities—deploy within one week
- Important-severity vulnerabilities—deploy within two weeks
Prioritise Systems Running Cloud or Container Workloads
CVE-2026-71331, a Critical remote code execution vulnerability affecting the Microsoft Azure Attestation service and Device Health Attestation Service. Remote code execution bugs are among the most serious vulnerability classes because successful exploitation may enable an attacker to run malicious code in the context of an affected service
.
If your organisation uses Windows containers or Device Health Attestation for endpoint trust validation, these systems require urgent patching.
Review Authentication and MFA Configurations
With elevation of privilege flaws dominating this month’s release, robust identity controls become even more critical. If you haven’t yet migrated away from SMS-based multi-factor authentication, read our guide on Microsoft’s retirement of SMS and voice call MFA and the transition to passkeys and passwordless authentication.
Test and Deploy Systematically
Even under time pressure, follow a structured deployment process:
- Test patches on non-production systems first (use a 4–8 hour test window for critical zero-days)
- Deploy to production systems in phases, starting with internet-facing infrastructure
- Monitor systems for 24 hours post-deployment to identify any compatibility issues
- Document which systems have been patched and which remain pending
The Bigger Picture: Patch Volumes Remain Elevated
Following its earlier warning that large-volume security updates could become the new norm for the foreseeable future, Microsoft this week released fixes for 421 unique CVEs
. This follows July’s record-breaking release and reflects
Microsoft warned that there would be an increase in Patch Tuesday security updates as it has begun to use an AI-powered vulnerability discover
y process.
For Kent SMEs, this trend creates two challenges:
- Resource pressure: Testing and deploying 400+ patches monthly requires dedicated time and systematic processes that many small IT teams struggle to resource
- Alert fatigue: As we discussed in our article on security alert fatigue, high volumes of security notifications can lead to critical warnings being overlooked
October Deadline Approaching for Multiple Microsoft Products
The next lifecycle changes with broad impact occur on October 14, 2026, when Windows 11 24H2 Home & Pro reach end of servicing, and Windows Server 2022 moves to extended support, with free critical security updates continuing, but no further feature development. At the same time, the final curtain falls for Windows Server 2012 and 2012 R2 with the expiry of the third and final year of cash-for-updates Extended Security Update (ESU) program for these aging workhorses. Office 2021 also moves beyond support
.
If you’re still running Windows 10 or older Microsoft 365 Apps, you have less than two months to plan your migration strategy.
Other Vendors Releasing Critical August 2026 Updates
Microsoft isn’t the only vendor releasing significant security updates this month. Kent SMEs should also prioritise:
- Adobe:
Adobe has released five security advisories addressing 51 vulnerabilities across Adobe ColdFusion, Adobe Commerce, Adobe Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. 33 of these vulnerabilities are rated critical - N-able:
N-able released security updates for an actively exploited authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers - Cisco: Multiple products including Catalyst SD-WAN and IOS XE have critical updates with public exploit code available
Don’t forget to check for pending Android security updates on company mobile devices as well.
Get Expert Support for Patch Management in Kent
Managing 400+ Microsoft vulnerabilities monthly alongside updates from Adobe, Google, Cisco, and other vendors requires systematic processes, testing infrastructure, and dedicated resources. For many Kent SMEs, maintaining this capability in-house simply isn’t practical or cost-effective.
Meridian Micro Limited provides comprehensive patch management services for businesses across Kent and the South East, including vulnerability assessment, prioritised deployment schedules, compatibility testing, and 24/7 monitoring to ensure your systems remain protected without disrupting operations.
If you’re struggling to keep pace with security updates or want to ensure critical zero-day vulnerabilities like CVE-2026-68820 are deployed promptly across your infrastructure, call our team on 01303 883111 for a no-obligation discussion about your patch management requirements.
