Microsoft Patched 400 Flaws This Week. Here's the Part That Applies to You.
William “BJ” Pote
CEO, eTop Technology
This week Microsoft shipped its August security update, and it was a big one: roughly 400 vulnerabilities fixed, including three zero-days, one of which attackers were already using before the patch existed.
You don’t need to read 400 CVE writeups. You need to know which handful change what your IT team or IT provider should be doing this week. Here’s that list, in plain English.
1. The zero-day attackers are already using: CVE-2026-68820
The headline: CVE-2026-68820 is a flaw in a low-level Windows networking driver (the Ancillary Function Driver for WinSock) that lets an attacker who already has a foothold on a machine elevate themselves to SYSTEM — the highest level of privilege Windows has. It was being exploited before the patch shipped: reporting ties the exploitation to North Korea’s Lazarus group, which used it to install a kernel-level rootkit. CISA added it to the Known Exploited Vulnerabilities catalog on August 11, the same day the patch came out.
Why it matters to SMBs: “An attacker who already has a foothold” sounds reassuring until you remember how footholds happen: a phishing email, a malicious document, a compromised browser session. Privilege-escalation bugs like this are the second half of nearly every serious intrusion. The first half gets the attacker onto one machine as a regular user. This bug turns that regular user into the machine’s owner — able to disable security tooling, harvest credentials, and move deeper into the network. When a flaw like this is on CISA’s KEV list, it isn’t theoretical. It’s in active use.
What to do:
- Apply the August Windows updates across every workstation and server. This is not a “next maintenance window” patch. Aim for days, not weeks.
- If your patching is automated (it should be), confirm the August cumulative update is actually landing — check the reporting, don’t assume. Machines that are off, off-network, or wedged on a failed update are the ones that get you.
- Ask whoever runs your IT one question: “What percentage of our machines have the August update installed, and when will it be 100?” A good provider answers with a number.
2. Two more zero-days, publicly disclosed before patching
The other two zero-days — CVE-2026-62832, nicknamed “LegacyHive,” in the Windows User Profile Service, and CVE-2026-72971 in a Windows container driver — were publicly disclosed before Microsoft patched them, which means attackers had a head start on studying them. Both are privilege-escalation flaws in the same family as the one above: they turn a small compromise into a full one.
There’s no separate action here. The same August update covers them. They’re extra weight on the same scale: this month’s update closes three known doors, one of which is confirmed in active use.
3. Critical flaws in Windows DNS, DHCP, and remote access services
The headline: Buried in the 400 are critical remote-code-execution flaws in Windows DNS Server, DHCP Server, and the Routing and Remote Access Service — plus more than a dozen critical bugs across Office apps including Word, Excel, and Access.
Why it matters to SMBs: In most small business networks, DNS and DHCP run on the same box as everything else: the domain controller. A remote-code-execution flaw in a service running on your domain controller is about as serious as it gets — that’s the server that holds every password hash in the company. The Office flaws matter for a different reason: they’re the kind that get triggered by opening a document someone emailed you.
What to do:
- Make sure servers are in the patch cycle, not just workstations. We regularly walk into environments where laptops patch automatically and the servers are months behind because “rebooting them is disruptive.” That tradeoff made sense in 2015. It doesn’t now.
- If you run your own domain controllers, patch and reboot them this week, in a planned window, in the right order. If your IT provider manages them, ask when it’s scheduled.
4. The SharePoint bypass being exploited right now: CVE-2026-55040
The headline: This one wasn’t patched this week — it was patched in July. It’s on this list because attackers started actively exploiting it this week, using a public proof-of-concept. CVE-2026-55040 is an authentication bypass rated 9.1 out of 10: by forging the tokens SharePoint uses to decide who’s logged in, an attacker can impersonate users — including administrators — on a vulnerable SharePoint server without any credentials. Researchers recorded a dozen exploitation attempts since mid-July, with the majority landing on August 12 and 13. It’s the fifth SharePoint flaw exploited in the wild this year.
Why it matters to SMBs: If your SharePoint lives inside Microsoft 365, patching it is Microsoft’s job and this isn’t your fire to fight. But plenty of businesses — especially in legal, engineering, and manufacturing — still run SharePoint Server on their own hardware, often supporting one legacy workflow nobody wants to touch. A month-old patch plus a public exploit plus active scanning is exactly the combination that gets unpatched servers compromised at scale. Attackers don’t find these servers by targeting you. They find them by scanning everyone.
What to do:
- Answer one question definitively: “Do we run SharePoint on any server we own?” If nobody knows, that’s the first problem.
- If yes, confirm the July 2026 SharePoint security updates are installed. Not “we think so” — confirmed, with the version number checked.
- If the server exists to support one old workflow, put a migration to SharePoint Online on the roadmap. Every year it stays on-prem is another year of months like this one.
The pattern this month
Two things are worth internalizing beyond the individual bugs.
The window between patch and exploitation keeps collapsing. The SharePoint flaw went from patched to proof-of-concept to active exploitation in about a month, and most of the observed attacks happened in a two-day burst this week. The WinSock zero-day was being exploited before the patch existed at all. If your patch cadence is “monthly, when convenient,” you’re structurally behind attackers who move in days.
Privilege escalation is the theme. All three zero-days are ways to turn a small foothold into full control. That’s a reminder that patching and prevention are half the game — the other half is detecting the initial foothold before it escalates. That’s what endpoint detection and response and managed monitoring exist for.
The bottom line
Four hundred fixes, three zero-days, one active exploitation campaign against a month-old patch. None of it made the evening news, and all of it is the normal operating tempo of 2026. Your business doesn’t need to track any of this — it needs to be able to answer, quickly and with numbers, “are we patched, and how do we know?”
If you can’t answer that today, book an intro call — qualifying businesses receive our $2,500 IT Risk Assessment complimentary. We’ll look at your actual patch coverage, your server update cadence, and what’s still running in your environment that shouldn’t be, and give you a prioritized punch list ranked by real risk.
We covered May’s vulnerability roundup here — the months keep looking like this. The businesses that do fine are the ones with a system, not the ones with luck.
William “BJ” Pote
CEO, eTop Technology
eTop Technology has spent over 15 years in IT and over 12 years serving the Inland Empire as a trusted managed IT provider. We host the Business Tech Playbook podcast and are passionate about helping business leaders make smarter technology decisions.