On August Patch Tuesday 2026, Microsoft released fixes for 421 security vulnerabilities – an unusually high number. Among them is an already actively exploited zero-day, plus several critical flaws that allow remote code execution. Users and administrators should update promptly.
The actively exploited zero-day
Considered already under attack is CVE-2026-68820: a use-after-free flaw in the WinSock driver (afd.sys). Attackers used it to elevate their privileges on a system all the way to SYSTEM level – gaining full control.
Critical remote attacks without user interaction
- Microsoft QUIC (CVE-2026-62815): a critical RCE flaw with a CVSS score of 9.8. An unauthenticated attacker can execute code remotely – with no action from the victim.
- Windows DNS Server: several critical RCE flaws (including CVE-2026-62878 and CVE-2026-62817) exploitable via crafted packets and without user interaction.
The DNS and QUIC fixes are especially urgent for server operators, since they can be exploited without authentication and without any user action. On home PCs, Windows Update usually installs the patches automatically – but a manual check does no harm.
Sources: SecurityWeek, Zero Day Initiative.



















