Industry News

Microsoft Patches Nearly 400 Flaws, Including One Already Being Exploited

Krebs on Security · 12 Aug 2026
Key Takeaway Prioritise installing this month's Windows updates promptly, starting with internet-facing and frequently used machines, and keep staff alert to phishing since attackers often combine it with flaws like these.

Microsoft has released updates for at least 398 security vulnerabilities in Windows and supported software. One of them is already being exploited by attackers, and two others were publicly detailed before the patches were released. Of the total, 42 are rated "critical", meaning attackers could potentially take remote control of a Windows computer with little to no help from the user.

The exploited flaw is CVE-2026-68820, a privilege escalation weakness in afd.sys, a core Windows driver that handles network socket connections. Security firm Automox says it is not a front-door bug but "step two in a chain": an attacker first phishes their way into a low-privilege foothold, then uses the driver flaw to take over the machine. The attack is difficult to pull off reliably, yet Automox notes that someone is clearly succeeding anyway.

Another privilege escalation flaw, CVE-2026-62832 in the Windows User Profile Service, is labelled by Microsoft as likely to be exploited and may be related to the recent "LegacyHive" disclosure by researcher Nightmare Eclipse. The third notable flaw, CVE-2026-72971, is a low-impact local tampering issue that Microsoft considers unlikely to be exploited.

This batch follows last month's record of more than 570 fixes and June's then-record of nearly 200. Microsoft attributes the surge to vulnerability discoveries aided by artificial intelligence, and experts expect hundreds of fixes per month to become normal.

Summarised by CISO AI from Krebs on Security, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.