In-app reader
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancillary Function Driver for WinSock affecting supported Windows client and server versions; a locally authenticated attacker with low privileges could run a specially crafted application to trigger a race condition and, if successful, gain SYSTEM privileges. The CVSS vector reflects local access, low privileges required, no user interaction, and high attack complexity because exploitation requires winning that race condition. Administrators should prioritize applying the relevant Windows security updates, particularly on systems where local code execution by untrusted users is possible, and monitor for suspicious privilege-escalation activity.
Windows User Profile Service Elevation of Privilege Vulnerability (CVE-2026-62832)
Microsoft says this vulnerability has been publicly disclosed but has not been exploited in the wild, making it a zero-day disclosure without confirmed exploitation at this time. Rated Important with a CVSS score of 7.8, this Windows User Profile Service flaw is an improper link resolution, or “link following,” issue that could allow a local authenticated attacker to elevate privileges. To exploit it, an attacker would need credentials for another local account and could run a specially crafted application to load another user’s registry hive; successful exploitation could allow access to or modification of another user’s data and ultimately grant administrator privileges. User interaction is not required. Administrators should prioritize applying the Microsoft security updates across affected Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025 systems, and should also limit local account reuse and monitor for unusual registry hive loading or profile service activity.
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability (CVE-2026-72971)
This vulnerability was publicly disclosed before Patch Tuesday, making it a zero-day, but Microsoft says it has not been exploited in the wild; it is rated Important with a CVSS score of 5.5. The flaw is an improper link-resolution, or “link following,” issue in the Windows Container Isolation file system filter driver, unionfs.sys, affecting Windows 11 Version 26H1 on x64 and ARM64 systems. A local, authenticated attacker could exploit it with low complexity and no user interaction to tamper with files, resulting in high integrity impact, though Microsoft rates confidentiality and availability impact as none. Administrators should apply the Windows updates that correct the driver’s link-handling behavior, particularly on systems using Windows containers or container isolation features.
Microsoft QUIC Remote Code Execution Vulnerability (CVE-2026-62815)
This Critical Microsoft QUIC remote code execution vulnerability is not listed as exploited in the wild or publicly disclosed. It carries a CVSS score of 9.8 and is a use-after-free flaw that could allow an unauthenticated remote attacker to send a specially crafted packet to an affected service over the network and execute code on the target system, with no user interaction required. Affected platforms include Windows 11 and Windows Server 2022/2025, including Server Core installations. Administrators should prioritize applying the Microsoft update, especially on systems exposing QUIC-enabled services to untrusted networks, and consider limiting network exposure where patching cannot be completed immediately.
Windows DNS Server Remote Code Execution Vulnerability (CVE-2026-62878)
Microsoft reports that CVE-2026-62878 is neither exploited in the wild nor publicly disclosed; it is a Critical Windows DNS Server remote code execution vulnerability with a CVSS score of 9.8. The flaw is a stack-based buffer overflow in Windows DNS that can be triggered remotely by an unauthenticated attacker sending a specially crafted packet to an affected service over the network, with no user interaction required, potentially allowing code execution on the target DNS server. Affected systems include multiple Windows Server releases from 2012 through 2025, as well as listed Windows 10 versions where the vulnerable component is present. Administrators should apply Microsoft’s security updates promptly, especially on DNS servers, and reduce exposure by limiting DNS service access to trusted networks where possible, blocking unnecessary inbound traffic at firewalls, and monitoring DNS servers for crashes or anomalous traffic patterns.
This was a summary of Microsoft’s monthly updates highlighting some important vulnerabilities. Prioritize the exploited WinSock privilege-escalation flaw, then the publicly disclosed User Profile Service and unionfs.sys issues, and patch internet-exposed QUIC services and DNS servers quickly due to remote code execution risk.
A detailed list of this month's vulnerabilities follows below. To search and filter them, visit my dashboard: https://patchlens.io
Description
CVE Disclosed Exploited Exploitability (old versions) current version Severity CVSS Base (AVG) CVSS Temporal (AVG)
.NET Core Remote Code Execution Vulnerability
Important 7.8 6.8
.NET Denial of Service Vulnerability
Important 7.5 6.5
.NET Elevation of Privilege Vulnerability
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
.NET Framework Elevation of Privilege Vulnerability
Important 8.8 7.7
Important 7.8 6.8
.NET Framework Remote Code Execution Vulnerability
Important 7.0 6.1
.NET Information Disclosure Vulnerability
Important 5.9 5.2
Important 6.5 5.7
.NET Security Feature Bypass Vulnerability
Important 5.9 5.2
AMD Zen Information Disclosure Vulnerability
Important 5.6 4.9
Important 5.6 4.9
Active Directory Security Feature Bypass Vulnerability
Important 5.3 4.6
Application Information Services Elevation of Privilege Vulnerability
Important 7.8 6.8
Application Insights Profiler Elevation of Privilege Vulnerability
(no customer action required)
Critical 8.8 7.7
Azure Active Directory Elevation of Privilege Vulnerability
(no customer action required)
Critical 9.9 8.6
Azure Confidential Ledger Remote Code Execution Vulnerability
(no customer action required)
Critical 9.1 7.9
Azure CycleCloud Elevation of Privilege Vulnerability
Important 8.1 7.1
Azure CycleCloud Information Disclosure Vulnerability
Important 6.5 5.7
Azure Entra ID Spoofing Vulnerability
(no customer action required)
Critical 8.8 7.7
Azure Logic Apps Information Disclosure Vulnerability
(no customer action required)
Critical 9.6 8.3
Azure Monitor Agent Elevation of Privilege Vulnerability
Important 7.2 6.3
Azure SQL Database Elevation of Privilege Vulnerability
(no customer action required)
Critical 7.8 6.8
Critical 10.0 8.7
Azure SQL Managed Instance Elevation of Privilege Vulnerability
(no customer action required)
Critical 8.7 7.6
Azure SRE Agent Elevation of Privilege Vulnerability
(no customer action required)
Critical 9.9 8.6
Azure Service Bus Remote Code Execution Vulnerability
(no customer action required)
Critical 9.9 8.6
Azure Storage Explorer Elevation of Privilege Vulnerability
Important 8.8 7.7
Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
Important 7.0 6.1
CoPilot Chat Security Feature Bypass Vulnerability
Important 7.1 6.2
Copilot Cowork Elevation of Privilege Vulnerability
(no customer action required)
Critical 9.3 8.1
Desktop Window Manager Elevation of Privilege Vulnerability
Important 7.8 6.8
Important 7.8 6.8
Important 7.0 6.1
GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Important 7.8 6.8
Microsoft 365 Admin Center Elevation of Privilege Vulnerability
(no customer action required)
Critical 9.8 8.5
Microsoft Access Remote Code Execution Vulnerability
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
(no customer action required)
Critical 9.4 8.2
Microsoft COM for Windows Information Disclosure Vulnerability
Important 5.5 4.8
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
Important 5.5 4.8
Microsoft Digest Authentication Elevation of Privilege Vulnerability
Important 7.8 6.8
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Important 6.5 5.7
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Important 8.8 7.7
Microsoft Dynamics Business Central Information Disclosure Vulnerability
Important 6.5 5.7
Microsoft Entra Connect Elevation of Privilege Vulnerability
Important 7.8 6.8
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
(no customer action required)
Critical 9.9 8.6
Microsoft Excel Information Disclosure Vulnerability
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 6.5 5.7
Important 6.5 5.7
Important 5.5 4.8
Important 5.5 4.8
Microsoft Excel Remote Code Execution Vulnerability
Important 8.8 7.7
Important 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Microsoft Exchange Server Denial of Service Vulnerability
Important 6.5 5.7
Microsoft Exchange Server Elevation of Privilege Vulnerability
Important 7.2 6.3
Important 6.5 5.7
Critical 8.0 7.0
Microsoft Exchange Server Remote Code Execution Vulnerability
Important 8.8 7.7
Microsoft Exchange Server Security Feature Bypass Vulnerability
Important 6.5 5.7
Microsoft Exchange Server Spoofing Vulnerability
Important 7.3 6.4
Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability
Important 8.8 7.7
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Important 9.8 8.5
Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability
Important 8.8 7.7
Microsoft Office Elevation of Privilege Vulnerability
Important 7.8 6.8
Microsoft Office Graphics Component Information Disclosure Vulnerability
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Microsoft Office Graphics Component Remote Code Execution Vulnerability
Critical 7.8 6.8
Critical 7.8 6.8
Critical 7.8 6.8
Critical 7.8 6.8
Critical 7.8 6.8
Microsoft Office Information Disclosure Vulnerability
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Microsoft Office Remote Code Execution Vulnerability
Critical 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Critical 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Critical 7.8 6.8
Critical 7.8 6.8
Critical 7.8 6.8
Critical 8.4 7.3
Microsoft Office SharePoint Spoofing Vulnerability
Important 8.0 7.0
Important 9.3 8.1
Critical 9.6 8.3
Microsoft Office Word Information Disclosure Vulnerability
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Important 5.5 4.8
Microsoft Office Word Remote Code Execution Vulnerability
Critical 7.8 6.8
Important 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Important 7.8 6.8
Critical 7.8 6.8
Important 7.8 6.8
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
Important 6.7 5.8
Microsoft Outlook Remote Code Execution Vulnerability
Important 8.8 7.7
Microsoft Outlook Spoofing Vulnerability
Important 4.3 3.8
Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
(no customer action required)
Critical 10.0 8.7
Microsoft PowerPoint Remote Code Execution Vulnerability
Important 7.8 6.8
Microsoft PowerShell Remote Code Execution Vulnerability
Important 8.8 7.7
Microsoft PowerShell Security Feature Bypass Vulnerability
Important 7.8 6.8
Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
(no customer action required)
Critical 8.8 7.7
Microsoft QUIC Information Disclosure Vulnerability
Important 7.5 6.5
Microsoft QUIC Remote Code Execution Vulnerability
Critical 9.8 8.5
Microsoft Remote Registry Service Denial of Service Vulnerability
Important 6.5 5.7
Important 6.5 5.7
Microsoft SharePoint Elevation of Privilege Vulnerability
Important 8.8 7.7
Microsoft SharePoint Remote Code Execution Vulnerability
Important 8.8 7.7
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Critical 8.8 7.7
Important 7.3 7.3
Critical 8.8 7.7
Important 8.8 7.7
Microsoft SharePoint Server Information Disclosure Vulnerability
Important 6.5 5.7
Microsoft SharePoint Server Remote Code Execution Vulnerability
Important 8.8 7.7
Important 8.1 7.1
Important 8.8 7.7
Important 8.8 7.7
Critical 8.8 7.7
Important 8.8 7.7
Important 8.8 7.7
Important 8.8 7.7
Microsoft SharePoint Server Spoofing Vulnerability
…(truncated for reading performance)
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.