Microsoft Security Bulletin with Updates and Patches for August 2026

Published:
Illustrative image about Microsoft Security Bulletin with Updates and Patches for August 2026

On August 12, 2026, INCIBE published the Microsoft Security Bulletin: August 2026, which reports 421 vulnerabilities detected in various Microsoft products. The severity assigned to these vulnerabilities is critical, as their exploitation could allow for remote code execution, privilege escalation, information disclosure, denial of service, bypassing security features, impersonation, and manipulation.

Highlighted Critical Vulnerabilities

Among the critical vulnerabilities, CVE-2026-68820 is particularly noteworthy as it is actively being exploited. This vulnerability allows for privilege escalation in the Windows Ancillary Function Driver for WinSock.

Other critical vulnerabilities include:

  • CVE-2026-71331: remote code execution in Windows Device Health Attestation (DHA).
  • CVE-2026-70332: impersonation in Microsoft Office SharePoint.
  • CVE-2026-70130: remote code execution in Microsoft Office.
  • CVE-2026-68823: remote code execution in Azure Confidential Ledger.
  • CVE-2026-68816, CVE-2026-68804, and CVE-2026-68794: remote code execution in Microsoft Excel.
  • CVE-2026-66807: remote code execution in Microsoft Office Graphics Component.
  • CVE-2026-66802: remote code execution in Windows Device Health Attestation.
  • CVE-2026-66799: privilege escalation in Windows Key Guard.
  • CVE-2026-65791: remote code execution in Windows iSCSI Target Service.
  • CVE-2026-65789: remote code execution in Windows DNS Server.
  • CVE-2026-65668: privilege escalation in Microsoft Purview eDiscovery.
  • CVE-2026-65667: privilege escalation in Microsoft Teams.
  • CVE-2026-65665: remote code execution in Microsoft SharePoint Server.
  • CVE-2026-65664 and CVE-2026-65657: remote code execution in Microsoft Office Graphics Component and Microsoft Office.
  • CVE-2026-64921: privilege escalation in Microsoft SharePoint Server.
  • Other remote code execution vulnerabilities in Microsoft Office and related components, including Word and Graphics Component, with identifiers from CVE-2026-64911 to CVE-2026-63515.
  • CVE-2026-63522: privilege escalation in Azure SQL Database.
  • CVE-2026-63508: privilege escalation in Microsoft Planetary Computer Pro.
  • CVE-2026-62918: impersonation in Microsoft Teams.
  • CVE-2026-62911: privilege escalation in Microsoft Exchange Server.
  • CVE-2026-62896: privilege escalation in Microsoft Teams.
  • CVE-2026-62893: remote code execution in Windows Deployment Services TFTP Server.
  • CVE-2026-62890: privilege escalation in Windows GDI+.
  • CVE-2026-62889: remote code execution in Windows Secure Socket Tunneling Protocol (SSTP).
  • CVE-2026-62878: remote code execution in Windows DNS Server.
  • CVE-2026-62873: privilege escalation in Microsoft 365 Admin Center.
  • CVE-2026-62869: impersonation in Azure Entra ID.
  • CVE-2026-62836, CVE-2026-62830: privilege escalation in Azure SQL Managed Instance and Azure SRE Agent.
  • CVE-2026-62827: privilege escalation in Microsoft SharePoint Server.
  • CVE-2026-62824: remote code execution in Remote Desktop Client.
  • CVE-2026-62823: remote code execution in Windows DHCP Server.
  • CVE-2026-62822: remote code execution in Windows GDI+.
  • CVE-2026-62820, CVE-2026-62819, CVE-2026-62818, CVE-2026-62817, CVE-2026-62816, CVE-2026-62815: remote code execution in various Windows components and services.
  • CVE-2026-59118, CVE-2026-59115: privilege escalation in Copilot Cowork and Microsoft Entra Provisioning Service.
  • CVE-2026-56162, CVE-2026-56161: privilege escalation and information disclosure in Azure SQL Database and Azure Logic Apps.
  • CVE-2026-50516, CVE-2026-50515: privilege escalation and remote code execution in Microsoft Azure Kubernetes Service and Azure Service Bus.
  • CVE-2026-50481: privilege escalation in Azure Active Directory.
  • CVE-2026-49163: privilege escalation in Application Insights Profiler.

Affected Product Families

Additional image about Microsoft Security Bulletin with Updates and Patches for August 2026

The product families affected by these vulnerabilities include:

  • Azure Defender
  • Developer Tools
  • Exchange Server
  • Office
  • Office 2016
  • Other
  • SharePoint Server
  • Windows

Availability and Application of Updates

Microsoft has released the corresponding security updates to mitigate these vulnerabilities. Their official page details the methods for applying the updates.

Applying these patches is the recommended measure to protect systems against the risks posed by these vulnerabilities and to prevent potential attacks, especially considering the CVE-2026-68820 vulnerability, which is already being exploited.

Original source: INCIBE - Microsoft Security Bulletin: August 2026

Reviewed by
Published: 15/08/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.