Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
The WinSock fix is one of the 398 patches issued today by Microsoft, and SAP’s fix for a vulnerability in Commerce Cloud is one of 29 patches this month.
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases.
The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-2026-68820), which, according to Todd Schell, principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges.
“Exploitation has already been detected,” noted Jack Bicer, director of vulnerability research at Action1, “making this the highest priority vulnerability in this month’s release.”
Separately, SAP issued 29 new and updated security patches, the most severe of which is CVE-2026-58231, with a CVSS score of 10. This is an improper authorization issue in SAP Commerce Cloud’s Data Hub Adapter.
42 critical Microsoft vulnerabilities
In total, Microsoft addressed 398 CVEs. Of them, 42 were rated critical, while 355 were rated Important. However, Tyler Reguly, associate director of security R&D at Fortra, noted that 236 CVEs affect Windows and are covered by a cumulative update. Another 98 are Office CVEs that are covered by separate Office cumulative updates, unless you happen to still run Office 2016
In addition to the actively exploited zero-day, Microsoft also warned of two other zero-days. CVE-2026-62832 is an elevation of privilege vulnerability in the Windows User Profile Service, rated Important. Action1 pointed out this has been publicly disclosed, so exploitation is likely; Ivanti noted that it is the flaw behind “LegacyHive,” the unpatched proof-of-concept released by researcher Nightmare-Eclipse just hours after July’s Patch Tuesday. This vulnerability lets a standard user coerce the User Profile Service into loading another user’s registry hive, even an administrator’s, to gain unauthorized access to that user’s Classes registry data.
CVE-2026-72971 is a tampering vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys), rated Important. Public disclosure ahead of the patch means exploit code could follow quickly, said Ivanti. It added that IT departments running Windows containers, build agents, or CI infrastructure on affected hosts should prioritize this update.
Satnam Narang, senior staff research engineer at Tenable, said CISOs should pay particular attention to the elevation of privilege flaw in the Windows Ancillary Function Driver (afd.sys) for WinSock, which handles socket commands. Not only was this vulnerability exploited in the wild, he said, it could be a flaw leveraged by nation state actors, as was 2024’s CVE-2024-38193, reportedly attacked by North Korean hackers linked to the Lazarus group. Tenable says historical tradecraft of this nature is typically leveraged by APT groups in limited, targeted attacks.
Many remote vulnerabilities this month don’t need authentication
A significant portion of this month’s risk comes from critical vulnerabilities that can potentially be exploited remotely, without authentication or user interaction, noted Action1’s Bicer. For example, he pointed out, Windows DNS Server Remote Code Execution Vulnerability (CVE-2026-62878), Microsoft QUIC Remote Code Execution Vulnerability, Windows iSCSI Target Service Remote Code Execution Vulnerability (CVE-2026-65791) and Windows Deployment Services TFTP Server Remote Code Execution Vulnerability each carries a CVSS score of 9.8.
“These vulnerabilities represent particularly serious attack paths because a malicious network request or packet could potentially lead directly to code execution,” Bicer said. “The TFTP Server Remote Code Execution Vulnerability (CVE-2026-62893) deserves additional attention because exploitation is assessed as more likely, despite no confirmed exploitation at publication.”
SharePoint represents another important concentration of risk, Bicer said. Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2026-65665) allows an authenticated attacker with at least Site Owner privileges to execute arbitrary code remotely, and is assessed as more likely to be exploited. The Microsoft SharePoint Server Elevation of Privilege Vulnerability (CVE-2026-62827) and a second Microsoft SharePoint Server Elevation of Privilege Vulnerability (CVE-2026-64921) can allow authenticated attackers with domain access to elevate themselves to SharePoint administrator.
“These vulnerabilities are particularly relevant where SharePoint contains sensitive corporate information or supports important business processes,” Bicer said. “A compromised identity could potentially become a path to administrative control, arbitrary code execution, information theft, or disruption of collaboration services.”
Advice for CSOs
For CSOs, the primary strategic priority should be reducing the window of exposure around CVE-2026-68820, because exploitation is already occurring, Bicer said. CVE-2026-62832 should follow closely, because it is publicly disclosed and assessed as more likely to be exploited. The next priority should be unauthenticated remote code execution vulnerabilities with low attack complexity, particularly Windows DNS Server Remote Code Execution Vulnerability, Microsoft QUIC Remote Code Execution Vulnerability, Windows iSCSI Target Service Remote Code Execution Vulnerability, and Windows Deployment Services TFTP Server Remote Code Execution Vulnerability.
He said IT leadership should also require accelerated remediation and explicit validation for DNS, DHCP, SharePoint, Exchange, Active Directory Certificate Services (AD CS), Routing and Remote Access Services (RRAS), Secure Socket Tunneling Protocol (SSTP), and other critical services. Because no documented workaround is identified for the highlighted vulnerabilities, Bicer said patch deployment remains the primary risk reduction measure. Systems that cannot be patched within established timelines, he added, should receive documented risk acceptance, exposure reduction, segmentation, enhanced monitoring, and compensating controls until remediation is complete.
‘The new normal’
“While this month’s release is smaller than last month’s, 398 new CVEs prove that massive patch loads are officially the ‘new normal,’” commented Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative. “The saving grace is that only one bug is currently being actively exploited. Security teams need to fix that zero-day today, but realize that managing this sheer volume of patches is now standard operating procedure.”
But security teams shouldn’t be awed by the hundreds of new CVEs this month, stressed Zack Finstad, VP of cybersecurity at Logically. “Volume alone is not the same as risk,” he said. “The practical move is to triage by exploitation status and internet exposure first, then work outward. A CVE that is already being exploited in the wild against internet-facing systems deserves a very different response than a theoretical local privilege escalation on an isolated workstation.”
SAP critical patches
The improper authorization vulnerability in SAP Commerce Cloud’s Data Hub Adapter (CVE-2026-58231) is the most critical of the patches released today, says Jonathan Stross, senior manager for cybersecurity research and innovation at Pathlock. An unauthenticated remote attacker with network access to an affected instance can submit crafted data to the Data Hub import endpoint, potentially leading to arbitrary code execution. Stross said successful exploitation could expose customer and order data, manipulate application behavior, interrupt storefront or integration flows, and compromise credentials or services trusted by the Commerce environment.
SAP also addressed two critical code injection flaws in Manufacturing Integration and Intelligence (MII), tracked as CVE-2026-44772 (with a CVSS score of 9.9) and CVE-2026-44758 (CVSS score of 9.1).
In a research note, Onapsis said the problem in MII is a vulnerable servlet component that is open to server-side template injection and server-side request forgery. The patch removes the vulnerable component.
Another critical defect is CVE-2026-34265 (CVSS score of 9.8), which is described as a memory corruption issue in Application Server ABAP for NetWeaver and ABAP Platform.
The memory corruption comes from logical errors in DIAG protocol parsing that allow an unauthenticated attacker to generate memory corruptions, said Onapsis. The vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application. Stross noted that an attacker does not require authentication to exploit this hole.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.