Microsoft's August 2026 security update addresses over 400 vulnerabilities, including three zero-day flaws that were exploited or publicly disclosed before patches were available.
The most urgent issue, CVE-2026-68820, is an elevation-of-privilege flaw in the Windows Ancillary Function Driver for WinSock, which Check Point linked to the North Korean group Lazarus.
The release includes 42 critical vulnerabilities, 37 of which could allow remote code execution, impacting various Windows products and complex codebases across the company's portfolio.