Microsoft's August security update fixes more than 400 flaws across Windows and Office, including a bug hackers are already using to break into machines.
- What it is: The August 2026 Patch Tuesday release addresses 421 vulnerabilities, including three zero-day flaws. One, CVE-2026-68820, is being actively exploited to gain elevated access on an affected device.
- Who is affected: Any Windows PC or server, and any Microsoft Office installation, that has not yet installed this month's updates.
- What the risk is: Attackers exploiting the flaw can escalate privileges and take broader control of an affected machine.
- What to do: Install Windows and Office updates as soon as possible. Microsoft recommends doing this within three days given the active exploitation.
We recommend confirming with your IT provider that this month's updates have been applied across all devices.