Patch Tuesday: August 2026 (Expel’s version)

By Matt Jastram

Published: August 13, 2026  •  1 minute read



Placeholder image for Patch Tuesday: August 2026 (Expel’s version)

TL;DR

  • This week’s Microsoft Patch Tuesday release included 398 CVEs for some fabulous summer reading, with three zero-days.
  • It includes 169 elevation of privilege CVEs, and 110 remote code execution (RCE) CVEs
  • We recommend prioritizing patching for the three identified zero-days immediately 

 

It’s late-summer—the time of year that kiddos head back to school and the summer nights are getting shorter. While many are closing out their vacations, Microsoft gave us back-to-back months with a massive CVE volume. Welcome to Patch Tuesday!

CVE ID Affects Affected versions CVSS Description

CVE-2026-68820

Windows Ancillary Function Driver for WinSock Elevation of Privilege Windows 10-10 

Windows 11-8

Windows Servers-12

(30 Total)

7.0 Can be exploited for administrator privileges

CVE-2026-62737

Windows Kernel Elevation of Privilege Vulnerability Windows 11-6

Windows Servers-2

(8 Total)

7.8 Can be exploited for administrator privileges

CVE-2026-62832

Windows User Profile Service Elevation of Privilege Vulnerability Windows 10-6

Windows 11-8

Windows Servers-4

(18 Total)

7.8 Can be exploited for administrator privileges

 

Patch Tuesday: August 11, 2026

Tuesday’s release included 398 CVEs, including fixes for three zero-day vulnerabilities. Here are the CVEs we think are deserving of your attention first: 

 

That’s it for this month. Questions? Reach out to your Expel representative or contact us here