August 2026 Patch Tuesday: the flaw attackers use after they're already in
Microsoft fixed roughly 400 flaws on August 11. Only one is being used in real attacks, and on its own it can't get anyone in. What that means for you.
Since early July, engineers at defense and aerospace companies in France, Germany, Brazil and India have been approached by recruiters who don't exist. The fake job offers were the way in. Once the attackers had a foothold on someone's machine, they reached for a Windows flaw that had no patch yet.
Microsoft released that patch on August 11, along with roughly 400 others. Out of the entire batch, it is the only flaw anyone is currently being attacked with — and on its own, it cannot get anybody into anything.
That gap is the useful part of this month.
(You'll see different totals in the news. SecurityWeek counts 421 using Microsoft's full release notes; the Zero Day Initiative counts 398. The difference is counting method, not danger.)
What the exploited flaw actually does
The bug is CVE-2026-68820, in a Windows component called the Ancillary Function Driver for WinSock — plumbing that handles network connections. Microsoft's own description is the part worth reading: "A locally authenticated attacker could run a specially crafted application on an affected system."
In plain English: to use this, an attacker has to already be running a program on your computer. It does not open the door. It promotes whoever is already inside from ordinary user to complete control of the machine — enough to switch off your security software and settle in quietly.
Check Point, whose researchers found it, traced the attacks to the North Korean group Lazarus and a long-running campaign built entirely on fraudulent recruitment offers. The fake recruiter was step one. This flaw was step two.
Almost every serious break-in works that way. Nobody starts with a kernel exploit. They start with a person, an email, or a password. The technical flaw is what turns a small foothold into a bad month.
Which means the honest way to read "400 fixes" is not we are in four hundred times more danger. It's: install the updates on a schedule, and keep your real attention on step one.
Two things worth asking about
Most of this month's other fixes install with a normal Windows update and need no thought from you. Two are worth a question — but only if your business owns a server, rather than just paying for Microsoft 365.
Windows DNS Server (CVE-2026-62878). Rated critical, and an attacker needs no password and no one to click anything. Dustin Childs of the Zero Day Initiative describes it as a buffer overflow "that ends up wormable" and suggests "testing and deploying this one quickly, especially to your Internet-facing DNS servers." Wormable means it can spread from machine to machine without any human help.
Exchange Server (CVE-2026-62911). This one lets an attacker slip past the login entirely and, in the Zero Day Initiative's words, "take over the mailboxes of all Exchange users." Working exploit code exists — it was demonstrated at the Pwn2Own hacking contest. Worth being clear about the name: this is Exchange Server, the email software a business runs on hardware it owns. If your email is Microsoft 365, Microsoft patches that side for you and there is nothing to install.
Three things this week
- Run Windows Update on every computer, then restart. Settings → Windows Update. An update sitting at "pending restart" hasn't protected anyone yet. Ten minutes per machine, or confirm your IT provider pushes them automatically.
- Send your IT provider one question, by name: "Do we run Exchange Server or Windows DNS Server on any machine of our own — and if so, are August's fixes installed?" A good provider answers the same day, and for most small businesses the answer is a clean no.
- Nothing about step one has changed. The fake recruiter, the invoice that isn't, the login page that looks right. That's still where attacks begin, and no Patch Tuesday will ever fix it.
Big months like this one are the new normal, by the way. Last month's release fixed 570 flaws — a record — because Microsoft has started using AI to hunt bugs in its own code. Expect the headline numbers to keep climbing while the number of flaws under real-world attack stays small.
If you're curious how step one and step two connect in your own setup, Tenant Strike maps attack paths — the routes real attackers use — onto the specific weak spots in your Microsoft 365 configuration. It's read-only, and there's nothing to install.
AI-researched from public sources, human-reviewed on August 17, 2026. We label AI-assisted writing — see our trust page.
See your own risk
Want this for your own Microsoft cloud?
Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.