Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

August 13, 2026

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

August 13, 2026

Microsoft Fixes 400 Flaws on August Patch Tuesday

August 13, 2026
Facebook X (Twitter) Instagram
Thursday, August 13
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Microsoft Fixes 400 Flaws on August Patch Tuesday
News

Microsoft Fixes 400 Flaws on August Patch Tuesday

Team-CWDBy Team-CWDAugust 13, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Microsoft turned up the heat on sysadmins for the second month in a row on August 11 with a Patch Tuesday comprising 400 CVEs, including one actively exploited zero-day vulnerability.

The figure is not quite as high as the record 570 issued in July’s Patch Tuesday but it will be a challenge to process for organizations without automated, risk-based patching programs.

The actively exploited zero day (CVE-2026-68820) is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock. A locally authenticated attacker with low privileges could run a specially crafted application and trigger a race condition to gain system privileges and extensive control over a targeted Windows system.  

“Confidentiality, integrity, and availability impacts are all rated high,” explained Action1 co-founder, Mike Walters. “Exploitation has been detected in the wild, so deployment should be prioritized even though the vulnerability is rated important rather than critical.”

Read more on Patch Tuesday: Microsoft Patches 570 CVEs in Record Patch Tuesday

Elsewhere, there were two publicly disclosed but as-yet-unexploited zero days published this month.

CVE-2026-62832 is an Elevation of Privilege (EoP) vulnerability in the Windows User Profile Service which could allow an authenticated local attacker to elevate privileges.

“An attacker with credentials for another local account could run a specially crafted application to load another user’s registry hive, potentially accessing or modifying that user’s data and gaining administrator privileges. No user interaction is required,” explained Action1 director of vulnerability research, Jack Bicer.

“Although active exploitation is not reported, organizations should prioritize deployment because successful exploitation could provide administrator privileges and compromise sensitive user data.”

The second publicly disclosed zero day which has yet to be exploited in the wild is CVE-2026-72971: a Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability.

Microsoft explained that authorized attackers could perform tampering locally due to “improper link resolution before file access” in the product.

“An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive,” it added. “Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required.”

The majority of CVEs addressed this month were elevation of privilege (EoP) and remote code execution (RCE) flaws. Some 37 of RCE bugs were rated “critical” out of a total of 42 critical vulnerabilities this month.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Next Article AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
Team-CWD
  • Website

Related Posts

News

Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

August 13, 2026
News

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

August 13, 2026
News

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

August 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Is Poshmark safe? How to buy and sell without getting scammed

February 19, 2026

A quick guide to recovering a hacked account

March 21, 2026

Common Apple Pay scams, and how to stay safe

January 22, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.