Microsoft has released its August 2026 security updates, fixing almost 400 vulnerabilities across Windows, Office, Exchange Server and other business tools – including one flaw already being used by attackers.
- What it is: The monthly "Patch Tuesday" update, covering 394 vulnerabilities, 62 of them rated critical, plus three zero-day flaws.
- Who is affected: Any business running Windows, Microsoft Office, Exchange Server, or related Microsoft products.
- What the risk is: One vulnerability, CVE-2026-68820, affecting a core Windows networking component, is already being actively exploited by attackers to gain elevated access on compromised machines.
- What action is needed: Ensure Windows Update and Microsoft 365 updates are set to install automatically, and confirm with your IT provider that patches have been applied across all devices and servers, including any on-premises Exchange Server.
We recommend prioritising this update cycle given the actively exploited flaw – get in touch if you would like us to confirm your systems are covered.
Source: BleepingComputer