Microsoft's August security update addresses 398 vulnerabilities, including a Windows kernel driver zero-day (CVE-2026-68820) that is currently being exploited in the wild.
The release includes four critical remote code execution flaws in Windows DNS Server, Deployment Services, QUIC protocol, and HPC Pack, each carrying a CVSS score of 9.8.
The update also completes a two-part fix for a SharePoint vulnerability chain, with the August patch addressing the RCE component following a July fix for an authentication bypass.