
Microsoft's August 2026 Patch Tuesday update addresses over 400 vulnerabilities, including CVE-2026-68820, a zero-day flaw in the Windows Ancillary Function Driver currently exploited in the wild.
The update fixes critical issues such as CVE-2026-62815, which allows unauthenticated remote code execution, and CVE-2026-63520, a SharePoint vulnerability discovered by Rapid7 researchers.
Security experts advise IT administrators to prioritize patching based on risk triage, noting that while the volume of reported bugs is high, active exploitation remains targeted.