Microsoft Patches Nearly 400 Security Vulnerabilities

Microsoft has released patches to fix at least 398 security vulnerabilities in Windows operating systems and related software, including one that is already being actively exploited.

By El Medio Oriente
August 17, 2026
The Microsoft logo and company sign are displayed in front of a modern office building with glass windows and architectural elements on a clear day.
Illustration. Microsoft headquarters illustrate a story about security patches released by the company to fix vulnerabilities in Windows and related software. (Foto: Coolcaesar / Wikimedia Commons (CC BY-SA 4.0))
3 min read
Text size

Microsoft today released updates to fix at least 398 security vulnerabilities in its Windows operating systems and compatible software, including a weakness that is already being actively exploited and two others that were publicly disclosed before today.

Microsoft's abundant August patch package did not exceed its historical release of more than 570 security updates the previous month, but it is double the historical June batch of nearly 200 fixes. Microsoft has attributed the recent avalanche of patches to vulnerability discoveries facilitated by artificial intelligence, and experts agree that Windows users should expect patch Tuesdays (the second Tuesday of each month) to cover hundreds of newly discovered security flaws.

Of the 398 vulnerabilities patched today, 42 earned Microsoft's most severe rating of "critical", meaning they are severe enough for malware or attackers to exploit and gain remote control over a Windows computer with little or no user assistance.

The only known "zero-day" flaw repaired by Microsoft this month is CVE-2026-68820, a privilege escalation vulnerability in a core Windows component called afd.sys, which security firm Automox describes as "the driver behind Windows socket connections on practically every machine". Automox stated that this "is not a main entry point flaw, but step two in an attack chain: an attacker gains low-privilege access through phishing, then uses the driver flaw to take control of the machine".

CVE-2026-62832 is another privilege escalation vulnerability that Microsoft has labelled as likely to be exploited; this flaw, in the Windows User Profile Service, may be related to the recent public disclosure "LegacyHive" by the bug hunter known as Nightmare Eclipse. The other publicly disclosed flaw is CVE-2026-72971, a low-impact local vulnerability that Microsoft considers unlikely to be exploited.

Other major software vendors are also increasing their patch volumes and frequency thanks to artificial intelligence, including Adobe, which last month moved to bimonthly security bulletins published on the second and fourth Tuesday of each month. Cisco, Google, Mozilla and Oracle are also releasing updates much more frequently and abundantly.

By all accounts, artificial intelligence is quite effective at finding security holes in software. But for now, at least, fixing the resulting vulnerability chaos remains a very human-focused effort, and the jury is still out on whether artificial intelligence technologies will be as good at fixing vulnerabilities as they are at finding and exploiting them. This is an important question considering these same artificial intelligence technologies also suggest fixes for the vulnerabilities they find.

Researchers from 1Password recently examined what happens when different large language models generate patches for newly disclosed and complex vulnerabilities. They found that the models generated patches that failed to fix the flaw or introduced a new weakness in the process, or both, more than half the time.

Ed Skoudis, president of the SANS Technology Institute, stated that his team has seen excellent results using artificial intelligence to generate patches, provided that humans are involved in the process to test the suggested fixes and drive iterative improvements.

Tyler Reguly of Fortra noted that although Microsoft's reports of patching hundreds of vulnerabilities at once have prompted some organisations to attempt to patch faster, it is important to keep in mind that only one of the nearly 400 flaws addressed today is known to be actively exploited. Reguly suggested that security leaders consult with their teams about how they are handling increasing workloads, which often involve testing fixes before deploying them in production environments.

Experts recommend backing up the system and data before applying this month's enormous patch batch. The day after each monthly Patch Tuesday is sometimes derisively referred to as "Reboot Wednesday", but there is generally no downside to waiting a few days to apply these huge update packages, as it sometimes takes a couple of days for Microsoft to properly fix occasionally problematic patches.

Microsoft Patches Nearly 400 Security Vulnerabilities | El Medio Oriente