Microsoft Patches 400 Vulnerabilities Including Active Zero-Day Flaw
Microsoft released security updates addressing 400 vulnerabilities, including one zero-day flaw currently being exploited by attackers to gain system privileges.
Microsoft released security updates on August 11 to address 400 vulnerabilities across its software ecosystem. The update includes a patch for CVE-2026-68820, a use-after-free flaw in the Windows Ancillary Function Driver for WinSock that is currently being exploited in the wild. This specific vulnerability allows a locally authenticated attacker with low privileges to escalate their access to system privileges.
In addition to the active exploit, the company patched two other publicly disclosed zero-day vulnerabilities that had not yet been exploited. These include an elevation of privilege flaw in the Windows User Profile Service (CVE-2026-62832) and a tampering vulnerability in the Windows Container Isolation FS Filter Driver (CVE-2026-72971).
Of the 400 total common vulnerabilities and exposures (CVEs) addressed, 42 were rated as critical. Within that critical group, 37 were identified as remote code execution bugs. The remaining vulnerabilities were primarily categorized as elevation of privilege and remote code execution flaws.