Microsoft Releases Fixes for 398 Security Vulnerabilities in August Update
Microsoft’s August security update addresses 398 vulnerabilities across Windows and supported software, including one flaw that the company says is being actively exploited. The release also covers tw...
Microsoft’s August security update addresses 398 vulnerabilities across Windows and supported software, including one flaw that the company says is being actively exploited. The release also covers two vulnerabilities that had been publicly disclosed before the patches became available.
The latest package is smaller than July’s record-setting release of more than 570 fixes, but it is roughly twice the size of June’s update. Microsoft has linked the growing number of reported vulnerabilities in part to the use of artificial intelligence in security research. Analysts expect large monthly patch bundles to become increasingly common as automated tools improve at identifying software weaknesses.
Forty-two of this month’s vulnerabilities received Microsoft’s “critical” severity rating. These flaws could allow remote code execution in circumstances where an attacker requires little or no user interaction.
Actively exploited Windows driver flaw
The known zero-day, tracked as CVE-2026-68820, is a privilege-escalation vulnerability in afd.sys, a Windows driver associated with network socket connections. Security researchers said exploitation appears to require an attacker to first obtain limited access, then repeatedly exploit a timing-sensitive condition to gain greater control of the system.
Microsoft also identified CVE-2026-62832, a privilege-escalation issue in the Windows User Profile Service, as likely to be exploited. Researchers have suggested it may be connected to a previously publicized issue known as “LegacyHive.” The third publicly disclosed vulnerability, CVE-2026-72971, involves local tampering and is considered less likely to be exploited.
AI-assisted patching remains challenging
The increase in AI-assisted vulnerability discovery is also raising questions about automated remediation. A 1Password study found that large language models failed to fully address complex vulnerabilities or introduced new weaknesses in more than half of the cases examined. Security experts said AI can still help produce fixes, but human review, testing and repeated refinement remain essential.
Organizations should prioritize the actively exploited issue while evaluating the broader update set against their own exposure and change-management requirements. Administrators are advised to back up systems and data, test updates where feasible, and monitor vendor guidance for reports of compatibility problems before broad deployment.
