Microsoft has released its biggest security update of the year, fixing more than 400 vulnerabilities across Windows, Office, Exchange Server and other business tools.
- What it is: August's Patch Tuesday release addresses 421 vulnerabilities, 62 of them rated critical, including three zero-day flaws, one of which is already being exploited.
- Who is affected: Any business running Windows devices, Exchange Server, SharePoint Server, or Microsoft Office.
- The risk: Unpatched systems are exposed to remote code execution and privilege escalation attacks, some of which are already being used by attackers.
- What to do: Ensure automatic updates are enabled and confirm this month's patches have been installed across all Windows devices and on-premises servers, particularly Exchange Server.
We recommend businesses prioritise this update cycle given the scale and severity of the fixes involved.