Microsoft Patches 398 Flaws, One Exploited
August's Patch Tuesday addresses 398 vulnerabilities, including an actively exploited zero-day, as AI-driven discovery swells update volumes.
Microsoft’s August Patch Tuesday release is here, and it is a hefty one. The company today shipped fixes for at least 398 security vulnerabilities across Windows and supported software, including one bug already being actively exploited in the wild and two others that were publicly disclosed before today. While this month’s bundle does not exceed last month’s record-breaking haul, it is more than double the nearly 200 fixes Microsoft issued in June, continuing a trend of increasingly massive update dumps.
AI Fuels Record Patch Volumes
Microsoft has attributed the recent surge in vulnerability discoveries to artificial intelligence, and security experts widely agree that Windows users should expect Patch Tuesdays—the second Tuesday of each month—to routinely cover hundreds of newly found flaws. The August release, while not eclipsing the more than 570 security updates pushed out last month, underscores how AI is reshaping the cadence and scale of software patching.
Critical Flaws and the Zero-Day
Of the 398 vulnerabilities patched today, 42 earned Microsoft’s most dire “critical” rating, meaning they are severe enough that malware or malcontents could exploit them to gain remote control over a Windows computer with little to no help from the user. The sole known zero-day fixed this month is CVE-2026-68820, a privilege escalation weakness in a core Windows component called afd.sys. Security firm Automox describes afd.sys as “the driver behind Windows socket connections on effectively every endpoint.”
Automox’s Landon Miles explained in a Patch Tuesday blog post that this is not a simple front-door bug. “This isn’t a front-door bug,” he wrote. “It’s step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box. The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”
Other Notable Vulnerabilities
Microsoft also patched CVE-2026-62832, another privilege escalation flaw in the Windows User Profile Service, which the company has labeled likely to be exploited. This bug may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local tampering vulnerability that Microsoft reckons is unlikely to be exploited.
A Growing Patch Deluge Across the Industry
Microsoft is not alone in ramping up patch volumes. Other major software makers are likewise increasing their patch output thanks to AI, including Adobe, which last month moved to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month. Cisco, Google, Mozilla, and Oracle are also shipping updates far more frequently and abundantly.
AI Finds Flaws, But Can It Fix Them?
By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse remains a heavily human-centric endeavor, and the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question when one considers that these same AI technologies also are suggesting fixes for the vulnerabilities they find.
Researchers at 1Password recently examined what happens when different large language models (LLMs) generate vulnerability patches for newly disclosed, complex vulnerabilities. They found the LLMs produced patches that failed to fix the flaw or added a new weakness in the process (or both) more than half the time.
Human Oversight Remains Key
Ed Skoudis, president of the SANS Technology Institute, said his team has seen excellent results using AI to generate patches, provided there are humans in the loop to test the suggested fixes and push for iterative improvements. “AI is rapidly becoming astonishingly good at finding vulnerabilities, but this research shows that fixing them is a very different problem,” Skoudis wrote in a SANS newsletter today. “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”
Don’t Rush the Updates
Tyler Reguly at Fortra says while reports of Microsoft patching hundreds of vulnerabilities in one go have prompted some organizations to try to patch faster, it’s important to bear in mind that only one of the almost 400 bugs addressed today is known to be actively exploited. Reguly suggested security leaders check in with their teams to see how they’re handling the increasing workloads, which often involve testing fixes before deploying them in production environments.
“If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made,” Reguly said. “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.”
Backup Before You Patch
Speaking of the humans behind the keyboards, don’t neglect to backup your system and/or data before applying this month’s monster patch load. The day after each month’s Patch Tuesday is sometimes derisively referred to as Reboot Wednesday, but it generally doesn’t hurt to wait a few days to apply these huge update bundles because it sometimes takes a couple of days for the occasional misbehaving patch to get ironed out properly by Microsoft.
What This Means for You
This month’s update cycle highlights a new reality for IT teams and individual users alike: patch management is no longer a once-a-month chore but a constant, high-volume operation. The sheer number of fixes—398 this month alone—means that prioritizing which patches to apply first is crucial, especially since only one is known to be actively exploited. Waiting a few days to ensure stability is prudent, but ignoring the updates entirely is not an option. As AI continues to accelerate the discovery of vulnerabilities, the burden on human admins to test, deploy, and verify fixes will only grow, making workflow adjustments and human oversight more critical than ever.
Sources
- Krebs on Security Original source
- examined Also reporting
Continue Reading
Chrome's New Defense Against Cookie Theft
Device-bound session credentials could curb account takeovers, but rollout is limited for now.
Zero-Click Zoom Flaw Hands Over the Room
A flaw in Zoom's annotation tool could let any participant take over a sharer's client — with zero clicks.
Zero-Day in Windows Winsock Kernel Driver Exploited in Attacks
Microsoft's August Patch Tuesday fixes 421 CVEs, including one exploited zero-day and two publicly disclosed flaws.