In-app reader
The August 2026 Security Update Review
__ August 11, 2026
__ Dustin Childs
I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “new normal”, it’s time to readjust what we consider a true bug apocalypse. This month’s release is thankfully smaller than last months, but still huge by historical standards. Take a break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for August 2026
For the first part of the August release, Adobe released five bulletins addressing 51 unique CVEs in Adobe ColdFusion, Commerce, Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic.
Here’s this month’s overview table:
Adobe Patches for August 2026
**
Bulletin ID Product CVE Count Highest Severity Highest CVSS Exploited Deployment Priority
APSB26-90 Adobe ColdFusion 15 Critical 10.0 No 1
APSB26-123 Adobe Campaign Classic 3 Critical 10.0 No 1
APSB26-92 Adobe Commerce 7 Critical 9.1 No 2
APSB26-94 Adobe Lightroom Classic 11 Critical 8.6 No 3
APSB26-111 Content Credentials SDK 15 Critical 7.5 No 3
TOTAL 5 bulletins 51
If you’re running Campaign Classic, that’s your priority. Not only is it a deployment priority of 1, but it also contains two different CVSS 10 bugs and supersedes the patch that was just released on August 3. ColdFusion is also deployment priority 1 and also contains a CVSS 10 bug. Adobe Commerce rates a priority 2 with code execution bugs as high as CVSS 9.1. The patches for Lightroom Classic and Content Credentials SDK are packed with CVEs, but only rate a deployment priority of 3.
None of the Adobe bugs receiving patches this month are listed as publicly known or under active attack at the time of release.
Microsoft Patches for August 2026
There are a couple of things to point out right at the beginning. Again, counting is difficult due to the size, but I see 398 new CVEs to go along with the other updates documented this month. However, there is only one listed being under active attack, so we’ve got that going for us, which is nice. The release impacts Windows and Windows components, Office and Office Components, AMD Zen, Azure and Azure Components, GitHub Copilot, Windows Defender, Exchange Server, SharePoint, OneDrive for macOS, Teams, Power BI, .NET and Visual Studio, DHCP Server and Client, DNS Server, and Windows TPM. Minecraft is absent from this release. All told, there are 62 rated Critical, one rated Moderate, with the rest rated Important in severity. Eight of these bugs were submitted through the ZDI program.
This volume of updates indeed seems to be the new normal – at least for now. What is interesting is that, while there is an explosion of bugs being reported (and fixed), there has been no equivalent increase in the number of bugs being actively exploited, at least as 0-days.
Again, we’ll start with the bug under active attack and move on from there.
CVE-2026-68820** - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability **This bug allows attackers to execute code at SYSTEM level. Bugs of this type are often paired with code execution bugs to take over a system, often through phishing or ransomware. One nitpick here: Microsoft lists the Exploit Code Maturity in the CVSS as “Unproven” but calls this out as actively exploited. Somewhere, that math ain’t mathing.
CVE-2026-62878** - Windows DNS Server Remote Code Execution Vulnerability **There are several DNS-related patches this month, but this one stands out by far. It allows a remote, unauthenticated attacker to execute code with elevated privileges without user interaction. It’s a good ol’ fashioned stack-based buffer overflow that ends up wormable. Microsoft states exploitation is less likely, but I wouldn’t count on that. I suggest testing and deploying this one quickly, especially to your Internet-facing DNS servers.
CVE-2026-62893** - Windows Deployment Services TFTP Server Remote Code Execution Vulnerability **This bug came through the ZDI program and allows for code execution without user authentication or user interaction. TFTP has no auth mechanism and is available remotely vid UDP port 69. Any WDS server serving Windows Imaging Format (WIM) files via TFTP (the standard PXE boot scenario) is vulnerable. The issue results from the lack of validating the existence of an object prior to performing operations on the object. UDP port 69 should be blocked at your perimeter, but this could easily be used by attackers for lateral movement within an enterprise. Again, test and deploy this one quickly if you’re using WDS for deployments in your enterprise.
CVE-2026-62815** - Microsoft QUIC Remote Code Execution Vulnerability **Here we have another remote, unauthenticated code execution bug that doesn’t require user interaction. This one is in the QUIC component. If you aren’t familiar with it, QUIC is an IETF-standardized transport protocol that runs over UDP instead of TCP, and it's the foundation for HTTP/3. Roughly 13.5 million websites rely on it. If you are one of those millions, test and deploy this patch rapidly.
CVE-2026-59124** - Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability **Don’t let the Important severity rating fool you; this is still a CVSS 9.8 bug. It gets knocked down since HPC isn’t on by default. However, it’s a hugely growing segment, and this is another remote, unauthenticated code execution bug that does not require user interaction. It might not be applicable to everyone, but if you’re using HPC in your environment, this is not one to sleep on, especially since Microsoft lists this as “exploitation more likely”.
CVE-2026-62911** - Microsoft Exchange Server Elevation of Privilege Vulnerability **There are several Exchange bugs in this release, but this one really stands out. It could allow a privilege escalation via an authentication bypass. If successful, an attacker could “take over the mailboxes of all Exchange users, attackers can send emails, read emails, download attachments.” This bug was one of the ones demonstrated at Pwn2Own Berlin, so ignore Microsoft’s exploitability and Exploit Code Maturity ratings. We handed them working exploits, so this is a real threat. As always, test out those Exchange updates before deploying, but don’t hurry up and schedule that downtime for your upgrade.
Here’s the full list of CVEs released by Microsoft for August 2026:
**
CVE Title Severity CVSS Public Exploited Type
CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability Important 7 No Yes EoP
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability Important 7.8 Yes No EoP
CVE-2026-49163 ** Application Insights Profiler Elevation of Privilege Vulnerability Critical 8.8 No No EoP
CVE-2026-50481 ** Azure Active Directory Elevation of Privilege Vulnerability Critical 9.9 No No EoP
CVE-2026-68823 ** Azure Confidential Ledger Remote Code Execution Vulnerability Critical 9.1 No No RCE
CVE-2026-62869 ** Azure Entra ID Spoofing Vulnerability Critical 8.8 No No Spoofing
CVE-2026-56161 ** Azure Logic Apps Information Disclosure Vulnerability Critical 9.6 No No Info
CVE-2026-50515 ** Azure Service Bus Remote Code Execution Vulnerability Critical 9.9 No No RCE
CVE-2026-56162 ** Azure SQL Database Elevation of Privilege Vulnerability Critical 10 No No EoP
CVE-2026-63522 ** Azure SQL Database Elevation of Privilege Vulnerability Critical 7.8 No No EoP
CVE-2026-62836 ** Azure SQL Managed Instance Elevation of Privilege Vulnerability Critical 8.7 No No EoP
CVE-2026-62830 ** Azure SRE Agent Elevation of Privilege Vulnerability Critical 9.9 No No EoP
CVE-2026-62873 ** Microsoft 365 Admin Center Elevation of Privilege Vulnerability Critical 9.8 No No EoP
CVE-2026-50516 ** Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability Critical 9.4 No No EoP
CVE-2026-59115 ** Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability Critical 9.9 No No EoP
CVE-2026-68794 Microsoft Excel Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-68804 Microsoft Excel Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-68816 Microsoft Excel Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability Critical 8 No No EoP
CVE-2026-63513 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-63519 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-63526 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-65664 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-66807 Microsoft Office Graphics Component Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-63515 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-63532 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-64898 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-64903 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-64909 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-64910 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-64911 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-65657 Microsoft Office Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-70130 Microsoft Office Remote Code Execution Vulnerability Critical 8.4 No No RCE
CVE-2026-70332 ** Microsoft Office SharePoint Spoofing Vulnerability Critical 9.6 No No Spoofing
CVE-2026-63518 Microsoft Office Word Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-63525 Microsoft Office Word Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-64907 Microsoft Office Word Remote Code Execution Vulnerability Critical 7.8 No No RCE
CVE-2026-63508 ** Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability Critical 10 No No EoP
CVE-2026-59118 ** Microsoft Power Apps Elevation of Privilege Vulnerability Critical 9.3 No No EoP
CVE-2026-65668 ** Microsoft Purview eDiscovery Elevation of Privilege Vulnerability Critical 8.8 No No EoP
CVE-2026-62815 Microsoft QUIC Remote Code Execution Vulnerability Critical 9.8 No No RCE
CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability Critical 8.8 No No EoP
CVE-2026-64921 Microsoft SharePoint Server Elevation of Privilege Vulnerability Critical 8.8 No No EoP
CVE-2026-65665 Microsoft SharePoint Server Remote Code Execution Vulnerability Critical 8.8 No No RCE
CVE-2026-62896 ** Microsoft Teams Elevation of Privilege Vulnerability Critical 9.6 No No EoP
CVE-2026-65667 ** Microsoft Teams Elevation of Privilege Vulnerability Critical 10 No No EoP
CVE-2026-62918 ** Microsoft Teams Spoofing Vulnerability Critical 7.5 No No Spoofing
CVE-2026-62824 Remote Desktop Client Remote Code Execution Vulnerability Critical 8.8 No No RCE
CVE-2026-62818 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability Critical 8.8 No No RCE
CVE-2026-62893 Windows Deployment Services TFTP Server Remote Code Execution Vulnerability Critical 9.8 No No RCE
CVE-2026-66802 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Critical 8.1 No No RCE
CVE-2026-71331 Windows Device Health Attestation (DHA) Remote Code Execution Vulnerability Critical 8.1 No No RCE
CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability Critical 8.8 No No RCE
CVE-2026-62817 Windows DNS Server Remote Code Execution Vulnerability Critical 8.8 No No RCE
CVE-2026-62820 Windows DNS Server Remote Code Execution Vulnerability Critical 8.1 No No RCE
CVE-2026-62878 Windows DNS Server Remote Code Execution Vulnerability Critical 9.8 No No RCE
CVE-2026-65789 Windows DNS Server Remote Code Execution Vulnerability Critical 8.1 No No RCE
CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability Critical 7.8 No No EoP
CVE-2026-62822 Windows GDI+ Remote Code Execution Vulnerability Critical 8.8 No No RCE
CVE-2026-65791 Windows iSCSI Target Service Remote Code Execution Vulnerability Critical 9.8 No No RCE
CVE-2026-66799 Windows Key Guard Elevation of Privilege Vulnerability Critical 7.8 No No EoP
CVE-2026-62816 Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability Critical 8.8 No No RCE
CVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Critical 8.1 No No RCE
CVE-2026-62889 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability Critical 8.1 No No RCE
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability Important 7.8 No No RCE
CVE-2026-62901 .NET Denial of Service Vulnerability Important 7.5 No No DoS
CVE-2026-58641 .NET Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-62871 .NET Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-62886 .NET Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-62909 .NET Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-62872 .NET Framework Elevation of Privilege Vulnerability Important 8.8 No No EoP
CVE-2026-65810 .NET Framework Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability Important 7 No No RCE
CVE-2026-62900 .NET Information Disclosure Vulnerability Important 5.9 No No Info
CVE-2026-62902 .NET Information Disclosure Vulnerability Important 6.5 No No Info
CVE-2026-62899 .NET Security Feature Bypass Vulnerability Important 5.9 No No SFB
CVE-2026-65777 Active Directory Security Feature Bypass Vulnerability Important 5.3 No No SFB
CVE-2026-59130 AMD Zen Information Disclosure Vulnerability Important 5.6 No No Info
CVE-2026-59131 AMD Zen Information Disclosure Vulnerability Important 5.6 No No Info
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability Important 7.5 No No Info
CVE-2026-61357 Application Information Services Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability Important 8.1 No No EoP
CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability Important 6.5 No No Info
CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability Important 7.2 No No EoP
CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability Important 8.8 No No EoP
CVE-2026-62892 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability Important 7 No No EoP
CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability Important 7.1 No No SFB
CVE-2026-65786 Desktop Window Manager Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-65787 Desktop Window Manager Elevation of Privilege Vulnerability Important 7.8 No No EoP
CVE-2026-65788 Desktop Window Manager Elevation of Privilege Vulnerability Important 7 No No EoP
[CVE-2026-70335](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-
…(truncated for reading performance)
Discussion
Sign in to join the discussion.
Keep reading
Optional: create a free account to save items, track programs, and sync across web + app. Reading stays free.