Microsoft August 2026 Patch Tuesday: 400+ Fixes, 3 Zero-Days

📑 Table of Contents
On August 11, 2026, Microsoft released its August Patch Tuesday — one of the largest security updates of the year. Security trackers counted roughly 400 vulnerabilities fixed across Windows, Office, Edge, and related software, including dozens rated critical and three zero-days: two publicly disclosed before a patch existed, and one already being exploited in the wild.
If you run Windows, this is the update to prioritize this month.
What got fixed
The exact counts vary by tracker because each vendor categorizes slightly differently — CrowdStrike logged 415 vulnerabilities, Rapid7 counted 421, and Belgium's national cyber center (CCB) listed 398 — but every tracker agrees on the shape of the release: a very large patch batch with a significant critical component. SANS ISC counted 62 vulnerabilities rated critical, with one being exploited in the wild and two publicly disclosed as zero-days before Microsoft shipped fixes. Qualys likewise reported three zero-day vulnerabilities: two publicly disclosed and one exploited.
The critical bucket is dominated by remote code execution (RCE) flaws — the kind that let an attacker execute code on your machine without meaningful user interaction. Trackers also flagged Windows elevation-of-privilege issues, which combine dangerously with RCE bugs: one lets an attacker in, the other lets them take full control.
The zero-days
Zero-days are the vulnerabilities that demand immediate attention, because attackers already know about them. In this release:
- Two were publicly disclosed ahead of Patch Tuesday, meaning the details were out in the open before Microsoft had a fix ready — putting unpatched systems at higher risk during the gap.
- One was confirmed as actively exploited in the wild. That is the one to treat as urgent: real attackers are using it right now.
For the actively exploited flaw, the guidance from security teams is essentially unanimous: patch immediately, before doing anything else.
Why this release matters
Patch Tuesday is routine — but this one stands out for three reasons.
First, scale. Roughly 400 vulnerabilities in a single month is at the high end of recent releases, and it reflects how much attack surface modern Windows carries: the kernel, browsers, Office document parsers, drivers, and a long tail of components that receive fewer headlines.
Second, the critical RCE count. Dozens of critical-severity flaws, most of them remote code execution, means a meaningful fraction of unpatched Windows machines are one bad interaction away from compromise — a malicious document, a booby-trapped webpage, or a crafted network request.
Third, the exploited zero-day. An in-the-wild exploit converts a theoretical risk into a present one. That alone justifies moving this update to the top of the queue.
There is also the compounding factor: many of these vulnerabilities chain together. An RCE gets you in; an elevation-of-privilege flaw gets you admin. Organizations that delay patching accumulate exposure across months of releases — and attackers know the delay window is their best opportunity.
What you should do
For individuals:
- Run Windows Update now — do not wait for automatic install to get around to it.
- Restart when prompted; many fixes only take effect after a reboot.
- Pay extra attention to the actively exploited zero-day fix — if you manage your own device, verify the update installed successfully.
- Update Edge and Office through their usual update channels, since Patch Tuesday covers them too.
For organizations:
- Treat this as a priority patch cycle, not a routine one — the exploited zero-day changes the calculus.
- Patch internet-facing systems and endpoints first, then the rest of the fleet.
- Confirm your patch-management tooling actually deployed the update; trackers routinely find a lag between release and installation.
- Keep an eye on vendor advisories (CrowdStrike, Qualys, SANS ISC, Rapid7) for post-release analysis, including any reports of the exploited flaw being used against real targets.
The sheer footprint helps explain the size of this release: Rapid7 counted 421 fixes, 236 of them in Windows alone — meaning close to 200 more landed across Office, Edge, and other components. A month like this is a reminder that Windows is not one product but a collection of attack surfaces, and each one needs its own fix.
The bottom line
Microsoft's August 2026 Patch Tuesday is not a small monthly cleanup — it is roughly 400 fixes, dozens of critical remote code execution bugs, and three zero-days, one of which is already being used in attacks. The update is available now. The window between disclosure and exploitation is shrinking, and this month, the exploit is already here.