Windows 11 & 10: August Patch Tuesday Closes Nearly 400 Security Holes

The updates close398 security vulnerabilities, 42 of them rated critical, and one already being actively exploited in the wild.


Fact checked, proudly created or enhanced with AI.


Microsoft has rolled out its August 2026 Patch Tuesday updates for Windows 11 and Windows 10, closing 398 security vulnerabilities, 42 of them rated critical, and one already being actively exploited in the wild. Alongside the security fixes, the update expands Secure Boot certificate rollout and delivers a handful of targeted bug fixes across supported Windows versions.

What's New

Windows 11 24H2 & 25H2 — KB5121003 Builds move to 26100.9168 (24H2) and 26200.9168 (25H2). Beyond the security patches, Microsoft further expands automatic device detection for the rollout of new Secure Boot certificates, which continue to be distributed gradually via Windows Update.

Windows 11 26H1 — KB5121000 Build 28000.2704. Fixes an incorrect Trusted Platform Module (TPM) maintenance status display, the Endorsement Key certificate now reports correctly after installing the update. This version also gets the expanded automatic Secure Boot certificate distribution mechanism.

Windows 11 23H2 — KB5120240 The most feature-heavy of this month's updates. Includes an updated mobile carrier profile for SolNet-Mobile, a reliability fix so devices managed via Mobile Device Management (MDM) keep working properly even after an MDM certificate expires, and a fix for File History so scheduled backups to SMB network shares reliably reach their network paths and copy files as expected. The emoji panel also switches its GIF source to GIPHY, following Google's retirement of the Tenor API.

Windows 10 22H2 — KB5120249 (ESU) Distributed under the Extended Security Updates program, this is primarily a security-only update, raising the build to 19045.7663. Microsoft lists no new features or major fixes for this release.

Security Highlights

  • CVE-2026-68820 (actively exploited zero-day): A privilege-escalation flaw in the afd.sys driver, which handles socket and network connections. An attacker with limited access to an already-compromised system could exploit a race condition to gain higher privileges. The attack is considered technically complex since it relies on precise timing.
  • CVE-2026-62832: A privilege-escalation issue in the Windows User Profile Service, possibly related to the previously disclosed "LegacyHive" flaw. Microsoft considers future exploitation likely.
  • CVE-2026-72971: A local, lower-impact tampering vulnerability that was already publicly known before this Patch Tuesday. Exploitation is currently considered unlikely.

Microsoft notes that the rising volume of vulnerabilities found each month is partly driven by increased use of AI tools in vulnerability research, which can scan large codebases faster than manual review, though AI-generated patches aren't yet trusted to fully close complex flaws on their own, so human review remains part of the fix pipeline.

Download

All August 2026 updates are available via Windows Update and the Microsoft Update Catalog:

about author