Microsoft's August 2026 Patch Tuesday update resolves 421 vulnerabilities, including 62 Critical-rated flaws and three zero-days that have been actively exploited. A notable vulnerability in Windows has been leveraged by the Lazarus group to gain SYSTEM privileges, highlighting the urgency of applying the patch. The update also addresses a publicly disclosed Windows privilege escalation flaw with a proof-of-concept and a newly completed unauthenticated SharePoint remote code execution vulnerability. While smaller than the previous month's record-breaking release, this update is still one of Microsoft's largest Patch Tuesday batches. The presence of zero-day activity targeting Microsoft vulnerabilities means that the window for patching is rapidly shrinking, making it essential for users to assess their exposure immediately1. This update is crucial for preventing potential attacks, as the exploitation of these vulnerabilities can have severe consequences for system security.
Patch Tuesday: Update now to fix 421 flaws, including three zero-days
⚠️ Critical Alert
Why This Matters
Zero-day activity targeting Microsoft means patching windows are already closing — assess your exposure immediately.
References
- Malwarebytes Labs. (2026, August 12). Patch Tuesday: Update now to fix 421 flaws, including three zero-days. *Malwarebytes*. https://www.malwarebytes.com/blog/bugs/2026/08/patch-tuesday-update-now-to-fix-421-flaws-including-three-zero-days
Original Source
Malwarebytes Labs
Read original →