Microsoft’s August 2026 Patch Tuesday releases address more than 400 vulnerabilities across Windows and other Microsoft products. Two outlets report the update includes one zero-day vulnerability that is already exploited in the wild, alongside additional flaws that require patching to prevent potential compromise.

The exploited zero-day is identified as CVE-2026-68820. SecurityWeek describes it as a use-after-free vulnerability in the Windows afd.sys kernel-mode driver (Windows Ancillary Function Driver for WinSock). Help Net Security adds that the flaw can allow a low-privileged, locally authenticated attacker to elevate privileges to SYSTEM by running a specially crafted application. Both outlets agree this is the key critical item in the release.

In addition to the exploited zero-day, both reports note that Microsoft patches a large set of other issues. Help Net Security specifies that three vulnerabilities were publicly disclosed before the patch was released, while SecurityWeek focuses on the total count of CVEs addressed. Other coverage differs mainly in how it emphasizes the number of fixes versus details of the exploited bug.