Your clients don’t care about 400 CVEs. They care if you slept.
Microsoft’s August 2026 Patch Tuesday ships ~400 fixes and three zero-days, including an actively exploited WinSock driver flaw. Here’s the priority list for South African MSPs and IT teams.
August 2026 Patch Tuesday: 400 fixes, one exploited WinSock zero-day — what SA MSPs should patch first
Microsoft’s August 2026 Patch Tuesday is out. It’s smaller than July’s record 570, but still a heavy month: roughly 400 vulnerabilities, 42 Critical, and three zero-days — one already used in real attacks.
If you manage Windows fleets for clients (or your own company), treat today as a deploy day, not a “read later” day.
The numbers (BleepingComputer count)
| Category | Approx. count |
|---|---|
| Elevation of privilege | 176 |
| Remote code execution | 110 |
| Information disclosure | 86 |
| Spoofing | 21 |
| Denial of service | 12 |
| Security feature bypass | 11 |
Of the Critical issues: 37 remote code execution and 5 elevation of privilege.
Counts vary slightly by vendor (Qualys reports ~421 including earlier-in-month cloud CVEs). For operational planning, use the Patch Tuesday-day figure: ~400.
Microsoft has also warned that Patch Tuesday volumes will keep rising as it uses AI-assisted vulnerability discovery across its codebase — expect big months to stay normal for a while.
Patch these first
1. CVE-2026-68820 — WinSock AFD driver (exploited in the wild)
What: Use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys). A locally authenticated attacker can win a race condition and reach SYSTEM. No user interaction required.
Why it matters: Microsoft confirms exploitation. Check Point reports Lazarus used it to deploy a new version of the FudModule kernel-mode rootkit.
Action: Deploy August cumulative updates on every Windows endpoint and server, then reboot. The fix is not active until restart. There is no workaround.
This is your emergency track for August — shared PCs, jump boxes, RDP hosts, and domain-joined workstations first.
2. CVE-2026-62832 — User Profile Service (“LegacyHive”) — publicly disclosed
What: Link-following flaw in the Windows User Profile Service. An authenticated attacker with credentials for another local account can load another user’s registry hive and escalate toward administrator privileges.
Why it matters: Publicly disclosed before the patch (matches the “LegacyHive” PoC from last month). Multi-user machines and admin workstations are the highest risk.
Action: Patch behind CVE-2026-68820, prioritising shared / privileged endpoints.
3. CVE-2026-72971 — Container Isolation FS filter — publicly disclosed
What: Tampering vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys).
Action: Include in the same August CU roll-out. Less urgent than the WinSock zero-day for most SMB MSP fleets, but do not leave it behind if you run containers or Windows Server container hosts.
Also in this release (MSP-relevant)
August is not only the three zero-days. Watch for:
- SharePoint Server — a large batch of RCE, elevation of privilege, and spoofing fixes (including Critical). On-prem and hybrid farms need a deliberate CU +
PSConfigpass. - Exchange Server — including Critical elevation of privilege (e.g. CVE-2026-62911).
- Microsoft Office — several Critical graphics / RCE issues. Keep Click-to-Run channels current.
- Active Directory Certificate Services (AD CS) — Critical RCE (CVE-2026-62818).
- Windows kernel / networking / Hyper-V / SMB — fold into the same monthly policy where clients run those roles.
Cumulative updates to track:
- Windows 11: KB5121003 / KB5120240 (version-dependent)
- Windows 10 ESU: KB5120249
Always confirm the exact KB for each build in MSRC or Windows Update history before you mark a client “done.”
A practical August roll-out for MSPs
- Approve August security CUs in your patch policy (test ring → pilot → production).
- Enforce reboot for CVE-2026-68820 — pending reboot = still exposed.
- SharePoint / Exchange — snapshot, stage CU, run farm tools (
PSConfigfor SharePoint), then production. - Office — verify channel and update status separately from OS CUs.
- Report — give clients a short note: what shipped, what you patched, what still needs a reboot window.
How Allocentra helps
If you run Allocentra, August is a good stress-test of the patch workflow:
- See which devices are missing the August cumulative update
- Approve by policy and deploy window (not inbox archaeology)
- Track reboot / compliance so “patched” means patched and restarted
- Pull a client-ready compliance view when they ask “are we patched?”
Patch day without a policy is just hope. Patch day with a policy is a checklist.
Sources
- Microsoft August 2026 Patch Tuesday — BleepingComputer
- MSRC Security Update Guide — August 2026
- Windows 11 KB5121003 & KB5120240
- Windows 10 KB5120249 ESU
Allocentra is an RMM + PSA platform for South African MSPs and IT teams, monitoring, patches, tickets, and alerts in one dashboard, priced in ZAR. Start a trial or book a demo.