Interestana
Home/News/Microsoft Patches 398 Security Vulnerabilities, Including Exploited Flaw
Krebs on Security3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Patches 398 Security Vulnerabilities, Including Exploited Flaw

Microsoft Patches 398 Security Vulnerabilities, Including Exploited Flaw

Microsoft released its August security updates, addressing a substantial 398 vulnerabilities across its Windows operating systems and supported software. This release, while not surpassing July's record-breaking 570 patches, significantly doubles the nearly 200 fixes issued in June. Microsoft has indicated that the recent surge in vulnerability discoveries is partly attributed to advancements in artificial intelligence, suggesting that users should anticipate frequent and extensive Patch Tuesday updates to address hundreds of newly identified security flaws. Among the 398 vulnerabilities patched, 42 were classified with Microsoft's highest severity rating, "critical." This designation signifies that these flaws are severe enough for malicious actors to exploit them for remote control of Windows computers with minimal user interaction. The single "zero day" vulnerability, identified as CVE-2026-68820, is a privilege escalation weakness within a fundamental Windows component known as afd.sys. This component functions as the driver for Windows socket connections across nearly all endpoints. Landon Miles from the security firm Automox described this flaw not as an initial entry point but as a secondary exploit, typically used after an attacker has already gained a low-privilege foothold through methods like phishing. The exploit's complexity is rated 7.0 due to the challenging nature of its race conditions, requiring repeated attempts for successful timing. Despite this complexity, evidence suggests the exploit is being successfully deployed. Another privilege escalation flaw, CVE-2026-62832, affecting the Windows User Profile Service, is also flagged by Microsoft as likely to be exploited and may be connected to the recent public disclosure of "LegacyHive" vulnerabilities. The company's proactive patching strategy, especially for actively exploited and publicly known vulnerabilities, aims to mitigate widespread security risks for its user base. The continuous discovery and patching of such a large number of vulnerabilities underscore the ongoing challenges in maintaining robust cybersecurity for complex operating systems like Windows. The reliance on AI in vulnerability discovery highlights a growing trend in cybersecurity, where advanced technologies are being leveraged by both defenders and attackers. This approach necessitates a continuous cycle of updates and vigilance from users to protect their systems against evolving threats.

Original source — read the full reporting at the publisher:

Read on Krebs on Security

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next