Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971.
This security-only release earns Patch Now for Windows, Office and Exchange; no SQL Server updates this month. Unfortunately, several critical issues affect server roles: Windows DNS Server carries a cluster of critical RCEs; Windows DHCP Server is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the Remote Desktop client, then a WinSock smoke test given the exploited afd.sys flaw. The Readiness team has provided a helpful infographic on the deployment risks for this Microsoft August update.
Both August client and server-side updates ship with empty known-issues lists. This may change over the coming days so checking back to the Microsoft Security Update Guide (MSRC) may be prudent. July’s open items have all closed: the Dell/Intel driver hold, the mid-July WSUS sync degradation, and the Emoji Panel GIF outage (August swaps in GIPHY).
One July item has been dropped from the documentation without a resolution note: the Windows Server 2022 BitLocker recovery prompt on first restart, for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team recommends that all recovery keys are (easily) retrievable before restarting freshly patched servers.
Between the July and August Patch Tuesdays (15 July to 10 August), the MSRC Security Update Guide revised 534 CVEs. Almost all these changes (458) were routine Microsoft Edge and Chromium re-publications – none of which required customer action. That leaves 76 touching Microsoft’s own products, 60 of them flagged customer action required, including:
The Readiness team has reviewed the 751 published updates, and it appears that Microsoft has not published any mitigations for updates in this August release.
Microsoft has not published any service or enforcement deadlines for this August. The 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November; dates below come from the linked Microsoft lifecycle pages.
One diary note: Windows 11 24H2 Home and Pro reach end of updates on 13 October 2026, two Patch Tuesdays out.
Microsoft’s August 2026 Patch Tuesday is a security-only release: 109 Windows test-guidance entries, four High Risk (July had 14). Printing and fonts lead: win32kfull.sys is the most-patched binary at seven entries and carries three of the four High Risk flags (32-bit printing on 64-bit Windows and font rendering); the Remote Desktop client carries the fourth. The testing guidance below works through each product and feature grouping.
Three of the four High Risk flags sit in win32k and touch print or font paths: 32-bit application printing on 64-bit Windows (two) and font rendering (one). GDI+, the Windows Imaging Component, and the kernel graphics driver (dxgkrnl.sys, five entries) change alongside; estates with 32-bit line-of-business printing or font-heavy documents take this first.
The RDP client carries the fourth High Risk flag; the fixes touch every redirection path and multi-session behaviour. RemoteApp, the display pipeline, and the RRAS and SSTP VPN stack change alongside.
The SMB client and server, NTFS and UDFS, the virtualised file layers (Cloud Files, Projected File System, Work Folders), and the platform stack (Hyper-V, virtual TPM, USB, and Windows Installer) all change. Standard Risk.
TAPI is the busiest component (11 entries) but carries only parity fixes; the rest spans TCP/IP, HTTP.sys, Windows Firewall, Bluetooth, wired 802.1X, and message queuing. Broad and shallow.
This August patch cycle affects click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office with the following updates:
On-premises Exchange takes a security update this month, seven CVEs across Exchange Server 2016, 2019, and Subscription Edition: one critical elevation of privilege and six important, spanning further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass.


