August 2026 Patch Tuesday: Windows flaw is exploited

Microsoft has released the August 2026 Security Updates. For small and midsized businesses, the key point is not the sheer number of vulnerabilities but one Windows issue that Microsoft already marks as exploited: CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock. In the Security Update Guide, Microsoft lists it as “Exploitation Detected”. That moves Windows clients and servers ahead of the usual monthly routine.

What Microsoft released on 11 August

The MSRC release notes list 421 Microsoft CVEs for August 2026. Several product families are covered, including Windows, Office, Exchange Server, SharePoint Server, Azure, Developer Tools and Defender. Windows is the largest block, with 236 vulnerabilities addressed. In the “Notable CVEs” table, Microsoft highlights two Windows issues: CVE-2026-62832 is publicly known, while CVE-2026-68820 is already being exploited.

That makes CVE-2026-68820 the item that should enter operational planning first. Its severity is “Important”, not “Critical”, but active exploitation in the wild makes it more urgent than many higher-rated issues that remain theoretical.

Which systems should be in scope

The vulnerable component is part of Windows. The MSRC data lists security updates for current Windows client and server versions, including Windows 11, Windows 10, Windows Server 2019, Windows Server 2022 and Windows Server 2025. The exact KB numbers vary by version; for Windows 11 version 25H2 Microsoft lists KB5121003, for Windows Server 2025 KB5120233, and for Windows 10 version 22H2 KB5120249.

  • First priority should be production Windows servers, terminal servers and machines with administrative tooling.
  • Next come Windows clients used by management, finance, help desk and IT administration.
  • Supported Windows 10 devices still need to be included if they remain in daily use.
  • For Server Core and hotpatch scenarios, the installed KB matters, not only the update approval.

Why local elevation of privilege matters

Microsoft describes CVE-2026-68820 as a use-after-free issue in the Windows Ancillary Function Driver for WinSock. According to the FAQ, a locally authenticated attacker could run a specially crafted application, trigger a race condition and, if successful, gain SYSTEM privileges. User interaction is not required.

At first glance, that may sound less dramatic than remote code execution. In real attack chains, however, local elevation of privilege is often the step that turns a compromised user account into full control of a machine. For organizations with 10 to 250 seats, this is exactly the risky scenario: one weak account, one phishing email or one downloaded tool can be enough for attackers to expand privileges after the initial foothold.

Timing and restarts: do not wait for the next cycle

Microsoft released the updates on 11 August 2026 and marks the affected products as “Customer Action Required”. The MSRC entry does not provide a separate workaround that would replace installing the updates. The Windows KB entries also state “Reboot Required: Yes”.

The practical deadline is therefore the next controlled maintenance window, not the next convenient patch slot several weeks away. If you update in stages, start with small pilot groups and then move through prioritized server and client rings. The restart is part of the fix; an update that has been downloaded but not rebooted does not reliably remove the exposure.

What companies should do now

For smaller IT teams, a clear sequence matters more than a long CVE spreadsheet. The combination of Microsoft’s “Exploitation Detected” status, SYSTEM privileges and broad Windows exposure is enough to treat CVE-2026-68820 as a special case in the August patch cycle.

  • Check your inventory: which Windows versions run on clients, servers, virtual machines and administrative workstations?
  • Bring patch rings forward and test updates for critical systems first, not last.
  • Use Microsoft Defender and existing EDR signals to look for unusual local privilege changes.
  • After restart, spot-check whether the expected KBs are actually installed.
  • Feed the results into a Microsoft Security Assessment if legacy devices or servers without maintenance windows appear.

Official Microsoft sources

If you are unsure whether all Windows systems have actually landed in the August patch cycle, we can review patch status, Defender signals and prioritized follow-up with you – get in touch.

Recommended Next Step

What does this mean for your environment?

Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

Sebastian Kerssen, Managing Director of ReByteIT

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.

Leave a comment