Technology

Microsoft’s August replace fixes a Home windows flaw that is already being attacked

The following scheduled Patch Tuesday might be on September eighth, 2026.

Home windows safety updates

Numerous the vulnerabilities—over 200 this time—are unfold throughout the assorted Home windows variations (10, 11, Server) for which Microsoft nonetheless supplies safety updates. Home windows 10’s help formally led to October 2025, however these enrolled within the Prolonged Safety Updates (ESU) program proceed to obtain safety updates till October 2027.

Assaults on Winsock

The one Home windows safety vulnerability on this month’s replace that’s already being exploited within the wild is the use-after-free (UAF) vulnerability CVE-2026-68820, within the Home windows auxiliary perform driver for Winsock. Attackers can acquire elevated privileges, permitting them to execute code with system privileges. To do that, they need to mix this exploit with one other distant code execution (RCE) vulnerability.

Vital Home windows vulnerabilities

Microsoft has categorized 18 Home windows safety vulnerabilities as essential. These embrace, for instance, the RCE vulnerability CVE-2026-62878 within the Home windows DNS server. If profitable, the buffer overflow may be exploited to execute code with elevated privileges with out person interplay.

The UAF vulnerability CVE-2026-62893 within the Trivial File Switch Protocol (TFTP) server of Home windows Deployment Providers could possibly be exploited through UDP port 69 to inject and execute code with out person interplay. The flaw stems from actions being carried out on an object with out first checking whether or not the article in query truly exists.

The RCE vulnerability CVE-2026-62815 in Fast UDP Web Connections (QUIC) can be used to execute injected code with out person interplay. Though solely categorized as excessive threat, it additionally accommodates the RCE vulnerability CVE-2026-59124. However since Microsoft’s Excessive Efficiency Computing (HPC) Pack isn’t enabled by default, the vulnerability isn’t thought-about essential—even when attackers might use it to execute injected code.