惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
GbyAI
GbyAI
Engineering at Meta
Engineering at Meta
有赞技术团队
有赞技术团队
博客园 - 【当耐特】
H
Hackread – Cybersecurity News, Data Breaches, AI and More
WordPress大学
WordPress大学
博客园_首页
美团技术团队
H
Help Net Security
MongoDB | Blog
MongoDB | Blog
宝玉的分享
宝玉的分享
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
J
Java Code Geeks
A
About on SuperTechFans
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
T
The Blog of Author Tim Ferriss
Microsoft Azure Blog
Microsoft Azure Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
雷峰网
雷峰网
爱范儿
爱范儿

Tenable Blog

How it works: Inside the agentic harness for Tenable Hexa AI Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI September 2026 Microsoft Patch Tuesday | Tenable® Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View” CVE-2026-75650: StyleSmuggler Adobe Commerce FAQ | Tenable® Why post-quantum defense starts with crypto visibility Building an exposure management program the business tr Tenable & SentinelOne: 93 CVEs Expose Edge Risk | Tenable® Siemens S7 PLC threat: What you need to know | Tenable® Oracle Critical Security Patch Update August 2026 | Tenable® How to detect & respond to cloud ransomware attacks in Azure Agentic AI Threat Cluster: What It Means for Your Exposure Agentic AI for Cybersecurity: See Security Teams Built at Black Hat USA 2026 An inside look at code security with Claude Mythos Preview Watch Tenable Hexa AI automate remediation with agentic routines How Claude Mythos Preview is changing code security at Tenable What do federal & state cyber rules mean for water utilities? What Canada’s Bill C-8 means for critical infrastructure security Minnesota Water Cyber Attack and CISA Advisory AA26-097A Oracle July 2026 Critical Patch Update 1235 CVEs | Tenable® AI agent config attacks: How attackers turn trusted Dev harness files into payloads wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable® SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® Build agentic AI security at Tenable Swarm, Black Hat 2026 SonicWall CVE-2026-15409 and CVE-2026-15410 zero-day exploited | Tenable® Understanding Anthropic’s new AI agent Claude Tag’s access model in Slack 5 reasons to integrate AppSec data with your exposure management platform July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs FedRAMP High, IL5, and zero trust: How federal agencies can secure cloud environments OMB M-26-14: Why federal agencies must fix asset visibility first
August 2026 Microsoft Patch Tuesday | Tenable®
Research Special Operations · 2026-08-12 · via Tenable Blog

9-minute read Aug 11 2026

A blog header image that includes a logo for Tenable Research Special Operations at the top. The image is for the Microsoft Patch Tuesday for August 2026 detailing 398 total CVEs. The severity breakdown is: 42 Critical, 355 Important, 1 Moderate, and 0 Low.

  1. 42Critical
  2. 355Important
  3. 1Moderate
  4. 0Low

Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.

Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.

A pie chart showing the severity distribution across the Patch Tuesday CVEs patched in August 2026.

This month’s update includes patches for:

  • .NET
  • .NET Core
  • .NET Framework
  • AMD Zen
  • Active Directory Certificate Services (AD CS)
  • Application Information Services
  • Azure Active Directory
  • Azure CycleCloud
  • Azure Monitor Agent
  • Azure Storage Explorer
  • Capability Access Management Service (camsvc)
  • Desktop Window Manager
  • Dynamics Business Central
  • GitHub Copilot and Visual Studio Code
  • Microsoft Azure Attestation service and Device Health Attestation Service
  • Microsoft COM for Windows
  • Microsoft Defender for Endpoint
  • Microsoft Digest Authentication
  • Microsoft Dynamics 365 (on-premises)
  • Microsoft Entra Connect Sync
  • Microsoft Exchange Server
  • Microsoft High Performance Computing (HPC) Pack
  • Microsoft Identity Services
  • Microsoft Local Security Authority Server (lsasrv)
  • Microsoft Office
  • Microsoft Office Access
  • Microsoft Office Excel
  • Microsoft Office Graphics Component
  • Microsoft Office Outlook
  • Microsoft Office PowerPoint
  • Microsoft Office SharePoint
  • Microsoft Office Word
  • Microsoft OneDrive
  • Microsoft PowerShell
  • Microsoft PowerShell Core
  • Microsoft QUIC
  • Microsoft Remote Registry Service
  • Microsoft Teams Mobile
  • Microsoft Teams for Android
  • Microsoft Windows Codecs Library
  • Microsoft Windows Media Foundation
  • Microsoft Windows Search Component
  • Power BI
  • RPC Runtime
  • Reliable Multicast Transport Driver (RMCAST)
  • Remote Desktop Client
  • User-Mode Power Service (UMPS)
  • Virtual Hard Disk (VHD) Miniport Driver
  • Visual Studio Code
  • Visual Studio Code - Python extension
  • Visual Studio Code CoPilot Chat Extension
  • Windows Accessibility Infrastructure (ATBroker.exe)
  • Windows Active Directory
  • Windows Ancillary Function Driver for WinSock
  • Windows Autopilot
  • Windows Backup Engine
  • Windows Bind Filter Driver
  • Windows Cloud Files Mini Filter Driver
  • Windows Common Log File System Driver
  • Windows Container Isolation FS Filter Driver (unionfs.sys)
  • Windows Cross Device Service
  • Windows DHCP Client
  • Windows DHCP Server
  • Windows DNS
  • Windows DWM Core Library
  • Windows Defender Firewall Service
  • Windows Deployment Services
  • Windows Device Association Service
  • Windows Display Enhancement Service
  • Windows Encrypting File System (EFS)
  • Windows Event Logging Service
  • Windows GDI
  • Windows GDI+
  • Windows Graphics Kernel
  • Windows HTTP Protocol Stack
  • Windows HTTP.sys
  • Windows Hello
  • Windows Hyper-V
  • Windows Imaging Component
  • Windows Installer
  • Windows Kerberos
  • Windows Kernel
  • Windows Key Guard
  • Windows LDAP - Lightweight Directory Access Protocol
  • Windows LUAFV
  • Windows License Manager
  • Windows MIDI Service Module
  • Windows Management Instrumentation
  • Windows Management Services
  • Windows Message Queuing
  • Windows Modern Device Management (MDM)
  • Windows NTFS
  • Windows Narrator Braille
  • Windows Network Address Translation (NAT)
  • Windows Network Connection Broker
  • Windows Network File System
  • Windows Package Manager
  • Windows Program Compatibility Assistant Service
  • Windows Projected File System
  • Windows Push Notifications
  • Windows RPC API
  • Windows Remote Access API
  • Windows Remote Access Connection Manager
  • Windows Remote Desktop Services
  • Windows Remote Help
  • Windows Remote Help Defense
  • Windows Routing and Remote Access Service (RRAS)
  • Windows SMB Client
  • Windows SMB Server
  • Windows Schannel
  • Windows Secure Socket Tunneling Protocol (SSTP)
  • Windows Sensor Data Service
  • Windows Shell
  • Windows Storage
  • Windows Storage Port Driver
  • Windows TCP/IP
  • Windows Telephony Service
  • Windows USB Driver
  • Windows Universal Disk Format File System Driver (UDFS)
  • Windows User Profile Service
  • Windows Win32K
  • Windows Wired AutoConfig Service
  • Windows Work Folder Service
  • Windows iSCSI Target Service
  • Winlogon

A bar chart showing the count by impact of CVEs patched in the August 2026 Patch Tuesday release.

Elevation of Privilege (EoP) vulnerabilities accounted for 40.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 27.1%.

CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2026-68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and was rated as important. A local attacker could exploit this vulnerability to elevate to SYSTEM privileges. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.

Two additional EoP vulnerabilities affecting this driver were patched this month. CVE-2026-61348 and CVE-2026-70307 also received CVSSv3 scores of 7.0, however no exploitation has been reported for these flaws. Both were assessed as "Exploitation More Likely" according to Microsoft's Exploitability Index.

Prior zero-days in this driver include CVE-2025-32709 in May 2025, CVE-2025-21418 in February 2025, and CVE-2024-38193 in August 2024.

CVE-2026-62832 | Windows User Profile Service Elevation of Privilege Vulnerability

CVE-2026-62832 is an elevation of privilege vulnerability affecting Windows User Profile Service. It received a CVSSv3 score of 7.8 and is rated as important. A local attacker could exploit this vulnerability to gain ADMINISTRATOR privileges. It was publicly disclosed prior to a patch being available and was assessed as “Exploitation More Likely.”

Historically, the Windows User Profile Service has received four total CVEs since January 2022. Prior zero-days in this family include CVE-2022-21919 in January 2022 and CVE-2022-26904 in April 2022.

CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability

CVE-2026-72971 is a tampering vulnerability affecting the Windows Container Isolation FS Filter Driver (unionfs.sys). It received a CVSSv3 score of 5.5 and is rated as important. It was publicly disclosed prior to a patch being available. Successful exploitation would allow a local attacker to perform tampering. Despite being publicly disclosed, Microsoft assesses this vulnerability as “Exploitation Unlikely.”

CVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

CVE-2026-62893 is a remote code execution vulnerability affecting Windows Deployment Services Trivial File Transfer Protocol (TFTP) Server. It received a CVSSv3 score of 9.8 and is rated as critical. It was assessed as "Exploitation More Likely." Successful exploitation of this flaw could occur when a remote, unauthenticated attacker sends crafted packets to a vulnerable service, resulting in code execution. It was reported to Microsoft by Nikolai Skliarenko of TrendAI Research.

CVE-2026-62823 | Windows DHCP Server Remote Code Execution Vulnerability

CVE-2026-62823 is a remote code execution vulnerability affecting Windows DHCP Server. It received a CVSSv3 score of 8.8 and is rated as critical. It was assessed as "Exploitation More Likely" according to Microsoft's Exploitability Index. Successful exploitation would allow a remote, unauthenticated attacker to execute code over an adjacent network by exploiting a heap-based buffer overflow flaw using a crafted packet.

13 additional Windows DHCP server vulnerabilities were patched this month, however these flaws were only rated as important. The flaws include eight information disclosure vulnerabilities with CVSSv3 scores of 6.5 (CVE-2026-62714, CVE-2026-62715, CVE-2026-62716, CVE-2026-62718, CVE-2026-62720, CVE-2026-62742, CVE-2026-62745 and CVE-2026-62814) and five EoP vulnerabilities with CVSSv3 scores of 7.8 (CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807 and CVE-2026-62812).

Multiple CVEs | Microsoft Office SharePoint Spoofing, Remote Code Execution, Elevation of Privilege, Information Disclosure and Tampering Vulnerabilities

This month's update includes patches for 29 CVEs affecting Microsoft Office SharePoint. Of the 29 CVEs, three were rated as critical and three were assessed as 'Exploitation More Likely.' A breakdown of the CVEs can be found in the table below:

CVEDescriptionCVSSv3SeverityExploitability Index
CVE-2026-70306Microsoft Office SharePoint Spoofing9.3ImportantExploitation Less Likely
CVE-2026-62827Microsoft SharePoint Server Elevation of Privilege8.8CriticalExploitation Less Likely
CVE-2026-65665Microsoft SharePoint Server Remote Code Execution8.8CriticalExploitation More Likely
CVE-2026-64921Microsoft SharePoint Server Elevation of Privilege8.8CriticalExploitation Less Likely
CVE-2026-63514Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less Likely
CVE-2026-64901Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less Likely
CVE-2026-65658Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less Likely
CVE-2026-65663Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less Likely
CVE-2026-66805Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less Likely
CVE-2026-66808Microsoft SharePoint Server Remote Code Execution8.8ImportantExploitation Less Likely
CVE-2026-70321Microsoft SharePoint Remote Code Execution8.8ImportantExploitation Less Likely
CVE-2026-70324Microsoft SharePoint Elevation of Privilege8.8ImportantExploitation Less Likely
CVE-2026-70326Microsoft SharePoint Server Elevation of Privilege8.8ImportantExploitation Less Likely
CVE-2026-63520Microsoft SharePoint Server Remote Code Execution8.1ImportantExploitation More Likely
CVE-2026-57105Microsoft Office SharePoint Spoofing8.0ImportantExploitation Less Likely
CVE-2026-70355Microsoft SharePoint Server Elevation of Privilege7.3ImportantExploitation More Likely
CVE-2026-58639Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less Likely
CVE-2026-62837Microsoft SharePoint Server Information Disclosure6.5ImportantExploitation Less Likely
CVE-2026-62839Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less Likely
CVE-2026-63512Microsoft SharePoint Server Tampering6.5ImportantExploitation Less Likely
CVE-2026-63516Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less Likely
CVE-2026-65660Microsoft SharePoint Server Spoofing6.5ImportantExploitation Less Likely
CVE-2026-62829Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less Likely
CVE-2026-62917Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less Likely
CVE-2026-64897Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less Likely
CVE-2026-64922Microsoft SharePoint Server Spoofing4.6ImportantExploitation Less Likely
CVE-2026-64900Microsoft SharePoint Server Spoofing7.3ImportantN/A
CVE-2026-64902Microsoft SharePoint Server Spoofing4.6ImportantN/A
CVE-2026-64916Microsoft SharePoint Server Spoofing4.6ImportantExploitation Unlikely

Tenable Solutions

A list of all the plugins released for Microsoft's August 2026 Patch Tuesday update can be found here. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.

For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on How to Perform Efficient Vulnerability Assessments with Tenable.

Get more information

Join Tenable's Research Special Operations (RSO) Team on Tenable Connect for further discussions on the latest cyber threats.

Learn more about Tenable One, the Exposure Management Platform for the modern attack surface.

Learn more

  • Exposure Management
  • Vulnerability Management