Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Microsoft fixed 421 flaws and said attackers used one Windows bug as a zero-day to deploy Lazarus rootkit malware.
- On Tuesday, August 11, 2026, Microsoft addressed 421 bugs in its latest Patch Tuesday release, including zero-day vulnerabilities exploited by North Korea's Lazarus Group.
- Lazarus continues its "Operation Dream Job" campaign targeting the defense sector in Europe and India, impersonating firms like Lockheed Martin and Enveil to distribute malware-laced documents to job seekers.
- Check Point researchers identified CVE-2026-68820 as a use-after-free flaw in the Windows Ancillary Function Driver; Lazarus deployed FudModule to execute code with SYSTEM-level privileges without user interaction.
- Trend Micro's Zero Day Initiative highlights CVE-2026-62893 in the Windows Deployment Services TFTP Server as critical; ZDI bug boss Dustin Childs urges enterprises to block UDP port 69 for protection.
- Microsoft also addressed CVE-2026-62911, an Exchange vulnerability demonstrated at Pwn2Own in Berlin, prompting security experts to advise rapid patching despite Microsoft deeming exploitation "less likely.
29 Articles
29 Articles
Disgruntled Researcher Discloses New Zero-Day in Windows Antivirus
The 'ShieldBreak' flaw can let an attacker use Windows Defender to escalate their privileges on the OS. Microsoft previously threatened legal action against the researcher, Nightmare Eclipse.
AI Scans Reveal Flaws at Scale, Driving Microsoft's Record Patch Tuesdays
Microsoft’s August Patch Tuesday landed with fixes for roughly 400 vulnerabilities, including three zero-days. That follows July’s record haul of 570 flaws patched in one cycle. Numbers like these mark a clear shift from earlier months, such as March’s total of just 83 issues addressed. Windows users now face larger updates more often. The pattern stems from deliberate changes inside Microsoft’s engineering process. Threat actors already deploy …
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
This is the latest zero-day released by security researcher Nightmare Eclipse, despite Microsoft publicly threatening to take legal action against them.
Why Microsoft Patch Tuesday Updates Suddenly Have So Many More Fixes
If you're a Windows user, you've hopefully installed regular Patch Tuesday updates from Microsoft, which address critical security vulnerabilities across the company's software. The last few months' worth of fixes have been especially important, as they've included a record number of bugs and a swath of zero-days that have been actively exploited or publicly disclosed. The August Patch Tuesday release this week is no different: The update fixes …
Microsoft released its monthly security updates, patching several critical vulnerabilities in the Windows operating system. In this article, we'll review the most prominent of these vulnerabilities and the importance of the updates. Microsoft released security updates to fix 398 vulnerabilities, including a zero-day vulnerability in the Windows kernel driver that was under active attack. Microsoft released its monthly security updates on Tuesday…
Coverage Details
Bias Distribution
- 80% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









