Today’s Patch Tuesday Alert addresses Microsoft’s August 2026 Security Updates. The FIRE team is actively working on coverage for these vulnerabilities and expect to ship that coverage as soon as it is completed.
In-the-Wild & Disclosed CVEs
A local attacker could potentially trigger a race condition in the Windows Ancillary Function Driver (AFD) for WinSock allowing for an elevation of privileges to SYSTEM level. Microsoft has reported this vulnerability as Exploitation Detected.
The Windows Container Isolation FS Filter Driver (unionfs.sys) does not properly validate if a referenced file is a link, allowing an authorized attacker to perform tampering. Microsoft has reported this vulnerability as Exploitation Unlikely.
An authenticated attacker who has credentials for a second local account could load another user’s registry hive which could ultimately lead to that user gaining administrative privileges. There are several indicators that this is tied to the LegacyHive disclosure, but we haven’t yet seen that confirmed. Microsoft has reported this vulnerability as Exploitation More Likely.
CVE Breakdown by Tag
While historical Microsoft Security Bulletin groupings are gone, Microsoft vulnerabilities are tagged with an identifier. This list provides a breakdown of the CVEs on a per tag basis. Vulnerabilities are also color coded to aid with identifying key issues.
- Traditional Software
- Mobile Software
- Cloud or Cloud Adjacent
- Vulnerabilities that are being exploited or that have been disclosed will be highlighted
| Tag | CVE Count | CVEs |
| Windows LUAFV | 1 | CVE-2026-50472 |
| Windows Narrator Braille | 1 | CVE-2026-56174 |
| Visual Studio Code | 7 | CVE-2026-58650, CVE-2026-59113, CVE-2026-47285, CVE-2026-69320, CVE-2026-69278, CVE-2026-69306, CVE-2026-70336 |
| Microsoft Teams for Android | 2 | CVE-2026-65768, CVE-2026-65767 |
| Microsoft Office SharePoint | 30 | CVE-2026-57105, CVE-2026-62829, CVE-2026-62827, CVE-2026-62837, CVE-2026-63514, CVE-2026-63512, CVE-2026-63516, CVE-2026-63520, CVE-2026-64922, CVE-2026-65658, CVE-2026-65663, CVE-2026-65660, CVE-2026-65665, CVE-2026-70321, CVE-2026-70324, CVE-2026-70355, CVE-2026-64897, CVE-2026-64900, CVE-2026-64902, CVE-2026-64901, CVE-2026-64916, CVE-2026-64921, CVE-2026-66805, CVE-2026-66808, CVE-2026-70306, CVE-2026-70326, CVE-2026-70332, CVE-2026-58639, CVE-2026-62839, CVE-2026-62917 |
| Microsoft Teams | 3 | CVE-2026-62896, CVE-2026-62918, CVE-2026-65667 |
| Azure SQL Managed Instance | 1 | CVE-2026-62836 |
| Microsoft Purview eDiscovery | 1 | CVE-2026-65668 |
| Azure Service Bus | 1 | CVE-2026-50515 |
| Microsoft Entra Provisioning Service (SyncFabric) | 1 | CVE-2026-59115 |
| Azure Active Directory | 1 | CVE-2026-50481 |
| Microsoft Planetary Computer Pro | 1 | CVE-2026-63508 |
| Microsoft 365 Admin Center | 1 | CVE-2026-62873 |
| Dynamics Business Central | 1 | CVE-2026-40375 |
| Windows Kernel | 9 | CVE-2026-54113, CVE-2026-61930, CVE-2026-62737, CVE-2026-61929, CVE-2026-62708, CVE-2026-62749, CVE-2026-62780, CVE-2026-62788, CVE-2026-65773 |
| Windows Imaging Component | 2 | CVE-2026-54984, CVE-2026-62740 |
| Windows Active Directory | 2 | CVE-2026-49179, CVE-2026-65777 |
| Microsoft PowerShell Core | 2 | CVE-2026-58612, CVE-2026-70337 |
| Azure Monitor Agent | 1 | CVE-2026-47299 |
| Microsoft High Performance Computing (HPC) Pack | 2 | CVE-2026-59124, CVE-2026-59133 |
| Windows Installer | 9 | CVE-2026-59127, CVE-2026-61925, CVE-2026-70344, CVE-2026-70345, CVE-2026-70346, CVE-2026-70347, CVE-2026-61938, CVE-2026-62768, CVE-2026-65774 |
| Windows Encrypting File System (EFS) | 1 | CVE-2026-59128 |
| AMD Zen | 2 | CVE-2026-59130, CVE-2026-59131 |
| Windows TCP/IP | 2 | CVE-2026-59132, CVE-2026-62792 |
| Microsoft Windows Search Component | 1 | CVE-2026-59135 |
| Remote Desktop Client | 7 | CVE-2026-59134, CVE-2026-61924, CVE-2026-61352, CVE-2026-61363, CVE-2026-61918, CVE-2026-61921, CVE-2026-62824 |
| Microsoft COM for Windows | 1 | CVE-2026-59136 |
| Windows Event Logging Service | 3 | CVE-2026-59137, CVE-2026-61347, CVE-2026-59126 |
| Microsoft Remote Registry Service | 2 | CVE-2026-59138, CVE-2026-61345 |
| Windows Graphics Kernel | 3 | CVE-2026-61346, CVE-2026-62702, CVE-2026-62774 |
| Windows Telephony Service | 11 | CVE-2026-61353, CVE-2026-62723, CVE-2026-62724, CVE-2026-62748, CVE-2026-62729, CVE-2026-59122, CVE-2026-62701, CVE-2026-62725, CVE-2026-62726, CVE-2026-62732, CVE-2026-62734 |
| Windows DHCP Client | 4 | CVE-2026-61361, CVE-2026-62755, CVE-2026-65785, CVE-2026-62736 |
| Windows Ancillary Function Driver for WinSock | 3 | CVE-2026-61348, CVE-2026-68820, CVE-2026-70307 |
| Windows NTFS | 8 | CVE-2026-61350, CVE-2026-62796, CVE-2026-62797, CVE-2026-65784, CVE-2026-62700, CVE-2026-62793, CVE-2026-62880, CVE-2026-62887 |
| Windows Remote Desktop Services | 5 | CVE-2026-61356, CVE-2026-61367, CVE-2026-62692, CVE-2026-61364, CVE-2026-61365 |
| Windows Display Enhancement Service | 1 | CVE-2026-61923 |
| Windows Network Connection Broker | 1 | CVE-2026-61366 |
| Windows Hyper-V | 1 | CVE-2026-61368 |
| Windows Bind Filter Driver | 4 | CVE-2026-61927, CVE-2026-61934, CVE-2026-62705, CVE-2026-62722 |
| Windows Hello | 1 | CVE-2026-61928 |
| Windows HTTP.sys | 6 | CVE-2026-61937, CVE-2026-62753, CVE-2026-62735, CVE-2026-62739, CVE-2026-62741, CVE-2026-62811 |
| Windows DWM Core Library | 5 | CVE-2026-61932, CVE-2026-61933, CVE-2026-62703, CVE-2026-62894, CVE-2026-62888 |
| Windows Defender Firewall Service | 1 | CVE-2026-61936 |
| Winlogon | 1 | CVE-2026-61939 |
| Windows Storage | 2 | CVE-2026-62695, CVE-2026-61359 |
| Windows MIDI Service Module | 2 | CVE-2026-62688, CVE-2026-62693 |
| Windows Push Notifications | 1 | CVE-2026-62690 |
| Windows Program Compatibility Assistant Service | 1 | CVE-2026-62696 |
| Windows Universal Disk Format File System Driver (UDFS) | 1 | CVE-2026-62699 |
| Windows Modern Device Management (MDM) | 1 | CVE-2026-62707 |
| Windows Cloud Files Mini Filter Driver | 2 | CVE-2026-62713, CVE-2026-62771 |
| Windows Win32K | 13 | CVE-2026-62712, CVE-2026-62746, CVE-2026-62798, CVE-2026-62876, CVE-2026-62877, CVE-2026-65678, CVE-2026-62711, CVE-2026-62733, CVE-2026-62743, CVE-2026-62786, CVE-2026-62885, CVE-2026-65775, CVE-2026-65776 |
| Windows DHCP Server | 14 | CVE-2026-62718, CVE-2026-62715, CVE-2026-62716, CVE-2026-62742, CVE-2026-62745, CVE-2026-62812, CVE-2026-62720, CVE-2026-62714, CVE-2026-62761, CVE-2026-62776, CVE-2026-62803, CVE-2026-62807, CVE-2026-62814, CVE-2026-62823 |
| Windows Message Queuing | 3 | CVE-2026-62719, CVE-2026-62717, CVE-2026-65790 |
| Windows Device Association Service | 2 | CVE-2026-62747, CVE-2026-62710 |
| Windows HTTP Protocol Stack | 1 | CVE-2026-62750 |
| Windows Kerberos | 4 | CVE-2026-62754, CVE-2026-62766, CVE-2026-62773, CVE-2026-62752 |
| Windows Remote Access Connection Manager | 2 | CVE-2026-62783, CVE-2026-62758 |
| Windows Container Isolation FS Filter Driver (unionfs.sys) | 3 | CVE-2026-62772, CVE-2026-72971, CVE-2026-62775 |
| Windows LDAP - Lightweight Directory Access Protocol | 2 | CVE-2026-62785, CVE-2026-62795 |
| Windows License Manager | 1 | CVE-2026-62777 |
| Windows Schannel | 2 | CVE-2026-62779, CVE-2026-62757 |
| Microsoft Local Security Authority Server (lsasrv) | 1 | CVE-2026-62784 |
| Windows DNS | 16 | CVE-2026-62787, CVE-2026-62817, CVE-2026-62820, CVE-2026-62878, CVE-2026-65789, CVE-2026-70304, CVE-2026-70330, CVE-2026-61920, CVE-2026-62769, CVE-2026-62778, CVE-2026-62881, CVE-2026-62883, CVE-2026-65795, CVE-2026-65797, CVE-2026-65799, CVE-2026-65798 |
| Microsoft QUIC | 2 | CVE-2026-62815, CVE-2026-62898 |
| Reliable Multicast Transport Driver (RMCAST) | 1 | CVE-2026-62816 |
| Active Directory Certificate Services (AD CS) | 1 | CVE-2026-62818 |
| Windows Routing and Remote Access Service (RRAS) | 1 | CVE-2026-62819 |
| Windows Secure Socket Tunneling Protocol (SSTP) | 1 | CVE-2026-62889 |
| Windows GDI+ | 3 | CVE-2026-62890, CVE-2026-62709, CVE-2026-62822 |
| Capability Access Management Service (camsvc) | 1 | CVE-2026-62892 |
| Windows Deployment Services | 1 | CVE-2026-62893 |
| .NET Framework | 3 | CVE-2026-62897, CVE-2026-62872, CVE-2026-65810 |
| .NET | 9 | CVE-2026-62899, CVE-2026-62900, CVE-2026-62901, CVE-2026-62902, CVE-2026-62909, CVE-2026-58641, CVE-2026-62871, CVE-2026-62886, CVE-2026-70354 |
| Windows Backup Engine | 1 | CVE-2026-62908 |
| Microsoft Exchange Server | 7 | CVE-2026-62910, CVE-2026-62912, CVE-2026-62913, CVE-2026-62914, CVE-2026-62915, CVE-2026-65813, CVE-2026-62911 |
| Microsoft Defender for Endpoint | 1 | CVE-2026-54123 |
| Microsoft Office | 29 | CVE-2026-63513, CVE-2026-63515, CVE-2026-63517, CVE-2026-63519, CVE-2026-65657, CVE-2026-65656, CVE-2026-65661, CVE-2026-65664, CVE-2026-68792, CVE-2026-70315, CVE-2026-70314, CVE-2026-70317, CVE-2026-70323, CVE-2026-62842, CVE-2026-63524, CVE-2026-63526, CVE-2026-63529, CVE-2026-63532, CVE-2026-63533, CVE-2026-64898, CVE-2026-64899, CVE-2026-64903, CVE-2026-64904, CVE-2026-64909, CVE-2026-64910, CVE-2026-64911, CVE-2026-66807, CVE-2026-66809, CVE-2026-70130 |
| Microsoft Office Word | 17 | CVE-2026-63518, CVE-2026-63521, CVE-2026-70311, CVE-2026-70310, CVE-2026-70319, CVE-2026-58651, CVE-2026-63525, CVE-2026-63528, CVE-2026-63527, CVE-2026-63530, CVE-2026-63531, CVE-2026-64905, CVE-2026-64907, CVE-2026-64915, CVE-2026-64917, CVE-2026-66806, CVE-2026-66810 |
| Windows GDI | 2 | CVE-2026-65662, CVE-2026-61360 |
| Windows Remote Access API | 2 | CVE-2026-65671, CVE-2026-65672 |
| Visual Studio Code CoPilot Chat Extension | 1 | CVE-2026-65675 |
| Desktop Window Manager | 3 | CVE-2026-65786, CVE-2026-65787, CVE-2026-65788 |
| Microsoft Office Excel | 28 | CVE-2026-65807, CVE-2026-68793, CVE-2026-68794, CVE-2026-68795, CVE-2026-68796, CVE-2026-68800, CVE-2026-68802, CVE-2026-68807, CVE-2026-68806, CVE-2026-68808, CVE-2026-68810, CVE-2026-68811, CVE-2026-68813, CVE-2026-68815, CVE-2026-68816, CVE-2026-70318, CVE-2026-70327, CVE-2026-70328, CVE-2026-68797, CVE-2026-68798, CVE-2026-68799, CVE-2026-68801, CVE-2026-68803, CVE-2026-68804, CVE-2026-68805, CVE-2026-68812, CVE-2026-68814, CVE-2026-68817 |
| Power BI | 1 | CVE-2026-65811 |
| Windows Storage Port Driver | 1 | CVE-2026-65814 |
| Microsoft Dynamics 365 (on-premises) | 2 | CVE-2026-65815, CVE-2026-66301 |
| Windows Key Guard | 1 | CVE-2026-66799 |
| Microsoft Office PowerPoint | 7 | CVE-2026-68809, CVE-2026-70312, CVE-2026-70313, CVE-2026-70316, CVE-2026-70325, CVE-2026-70320, CVE-2026-70322 |
| Windows Network File System | 1 | CVE-2026-68819 |
| Windows Package Manager | 1 | CVE-2026-68821 |
| Microsoft Teams Mobile | 1 | CVE-2026-65769 |
| Microsoft Office Outlook | 2 | CVE-2026-70329, CVE-2026-62882 |
| GitHub Copilot and Visual Studio Code | 1 | CVE-2026-70335 |
| Azure Storage Explorer | 1 | CVE-2026-57104 |
| Azure CycleCloud | 2 | CVE-2026-70340, CVE-2026-65806 |
| Windows Autopilot | 6 | CVE-2026-65783, CVE-2026-65779, CVE-2026-65780, CVE-2026-65778, CVE-2026-65782, CVE-2026-65781 |
| Windows Cross Device Service | 1 | CVE-2026-66804 |
| Windows Management Services | 1 | CVE-2026-70348 |
| Windows RPC API | 1 | CVE-2026-42976 |
| Visual Studio Code - Python extension | 1 | CVE-2026-54981 |
| Microsoft PowerShell | 2 | CVE-2026-59119, CVE-2026-70338 |
| Virtual Hard Disk (VHD) Miniport Driver | 1 | CVE-2026-59125 |
| Windows Work Folder Service | 1 | CVE-2026-61349 |
| Windows Sensor Data Service | 1 | CVE-2026-61355 |
| Application Information Services | 1 | CVE-2026-61357 |
| Windows Accessibility Infrastructure (ATBroker.exe) | 1 | CVE-2026-61358 |
| Windows USB Driver | 1 | CVE-2026-61926 |
| Microsoft Digest Authentication | 1 | CVE-2026-62698 |
| User-Mode Power Service (UMPS) | 1 | CVE-2026-62721 |
| Windows Common Log File System Driver | 1 | CVE-2026-62728 |
| Windows Wired AutoConfig Service | 1 | CVE-2026-62730 |
| Windows Projected File System | 1 | CVE-2026-62751 |
| Windows Shell | 1 | CVE-2026-62770 |
| Windows SMB Client | 3 | CVE-2026-62799, CVE-2026-62782, CVE-2026-65794 |
| RPC Runtime | 1 | CVE-2026-62781 |
| Windows SMB Server | 2 | CVE-2026-62800, CVE-2026-62790 |
| Windows User Profile Service | 1 | CVE-2026-62832 |
| Microsoft Office Access | 6 | CVE-2026-64906, CVE-2026-64912, CVE-2026-64908, CVE-2026-64914, CVE-2026-64920, CVE-2026-64919 |
| Microsoft Entra Connect Sync | 1 | CVE-2026-65673 |
| Windows iSCSI Target Service | 4 | CVE-2026-65681, CVE-2026-65679, CVE-2026-65791, CVE-2026-65796 |
| Microsoft OneDrive | 1 | CVE-2026-65680 |
| Microsoft Azure Attestation service and Device Health Attestation Service | 2 | CVE-2026-66802, CVE-2026-71331 |
| Windows Network Address Translation (NAT) | 1 | CVE-2026-56179 |
| Azure SQL Database | 2 | CVE-2026-63522, CVE-2026-56162 |
| Windows Management Instrumentation | 1 | CVE-2026-62738 |
| Azure SRE Agent | 1 | CVE-2026-62830 |
| Azure Logic Apps | 1 | CVE-2026-56161 |
| Microsoft Power Apps | 1 | CVE-2026-59118 |
| Microsoft Azure Kubernetes Service | 1 | CVE-2026-50516 |
| Application Insights Profiler | 1 | CVE-2026-49163 |
| Azure Confidential Ledger | 1 | CVE-2026-68823 |
| Azure Entra ID | 1 | CVE-2026-62869 |
Other Information
At the time of publication, there were no new advisories included with the August Security Guidance.