Security 10976 Published by

Microsoft's August 2026 Patch Tuesday addresses a staggering 421 CVEs across Windows, Office, Exchange, SharePoint, and Azure, with the most urgent fix targeting a WinSock driver flaw actively exploited in the wild. Windows 11 users should install cumulative update KB5121003, which brings builds 26200.9168 and 26100.9168 to versions 25H2 and 24H2, while eligible devices can apply the patch hotpatch-style without a reboot. The release also quietly patches two TPM 2.0 hardware vulnerabilities and rolls out minor UX tweaks like better File Explorer unit formatting and desktop fingerprint support for Windows Hello. IT teams need to deploy these fixes immediately, especially since Windows 11 version 24H2 Home and Pro editions will lose support in just over two months.





Microsoft's August Patch Tuesday tackles 421 vulnerabilities, including a WinSock flaw actively exploited in the wild

Windows, Office, and Azure all receive critical fixes as IT shops race to deploy KB5121003 before end-of-life deadlines loom.

Microsoft released its August 2026 security updates on Tuesday, and this month's Patch Tuesday is one of the heaviest in years. The company is addressing 421 CVEs across Windows, Office, Exchange Server, SharePoint, Azure, and developer tools. The most urgent fix targets a WinSock driver vulnerability that threat actors have already weaponized.

Active exploitation is never a good time to procrastinate on a security patch. CVE-2026-68820 sits inside the Windows Ancillary Function Driver for WinSock and stems from a use-after-free condition. Attackers with local access can use it to escalate privileges, and Microsoft has confirmed real-world exploitation. That makes this a priority update for any Windows server or desktop that has not already run Windows Update.

Wsec

Windows Update Breakdown

The Windows 11 cumulative update, KB5121003, pushes builds 26200.9168 for version 25H2 and 26100.9168 for 24H2. You are looking at roughly 5.3 gigabytes for the x64 installer, though arm64 builds sit closer to 4.9 GB. Since it is a cumulative rollup, it bundles every security and non-security fix Microsoft has shipped since the version launched.

Hotpatching is also back on the calendar. August is marked as a hotpatch month for both 24H2 and 25H2, meaning eligible devices enrolled in Autopatch or configured for restart-free updates will receive KB5121003 without a reboot. If your IT department already approved Windows Server hotpatching for Azure VMs, that rollout should accelerate now that the feature hit general availability. It is a rather heavy install for what amounts to mostly privilege escalation and TPM logic fixes, though the cumulative nature means you are also getting every non-security tweak Microsoft shipped this year.

The TPM Problem Keeps Popping Up

Two separate Trusted Platform Module vulnerabilities made it into this round, both originally reported to the Trusted Computing Group and assigned CVEs by MITRE. CVE-2026-6726 covers a TPM 2.0 object slot reuse flaw that can enable spoofing attacks, while CVE-2026-6727 targets an RSA OAEP timing side-channel that leaks information through observable delays.

Hardware-level security bugs tend to fly under the radar until they surface in research papers, but TPM vulnerabilities carry a different weight. You cannot patch a silicon bug with a Windows Update. A firmware drop from your OEM handles the actual memory rewrite. The OS just stops trying to route around the flaw. Keep in mind that these fixes apply to the reference implementation, which means firmware and driver updates from your hardware vendor will likely be required to fully close the gap. That is a slower process than pushing a KB article to your domain.

Last August's patch sat at roughly 180 CVEs. This month more than doubles that tally. The spike in vulnerability volume likely reflects Microsoft's ongoing push to audit legacy code paths and third-party drivers ahead of the Windows 11 25H2 mainstream cycle.

What Else Is Changing

The non-security changes rolling out alongside the patch are lighter than usual, but a few stand out. File Explorer will finally display sizes using appropriate units in Details view instead of forcing everything into kilobytes. Windows Hello Extended Sign-in Security is also beginning to roll out fingerprint support for desktops, which should make multi-factor biometrics a bit more practical for tower builds. Voice Access got a voice isolation boost and now supports Korean.

There is also a hard deadline creeping up. Windows 11 version 24H2 Home and Pro editions reach end of life on October 13, 2026. After that date, those installations stop receiving monthly rollups. If you are still running 24H2 on consumer-tier licenses, August is effectively the last patch you will get before migration becomes mandatory. Enterprise and Education editions get another year, but the clock is already ticking.

Organizations should push KB5121003 to production environments immediately, especially on Exchange Server and Windows Server builds. The companion KB articles for known issues, including hotpatch complications for Server 2025 and subscription edition Exchange quirks, are already live on the Microsoft Update Catalog. Head here to pull the direct download or approve it in your WSUS and Intune consoles.