ZeroHour
Tenable Blogpublished ()ingested Research Special Operations1

Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)

highVulnerability exploited in the wildimportance 77CVE-2026-68820CVE-2026-6726CVE-2026-6727
AI summary · glm-5.3-flash

Tenable reports Microsoft's August 2026 Patch Tuesday addresses 398 CVEs including three zero-days, one exploited in the wild (CVE-2026-68820).

Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 important, and one moderate, and three zero-days among them. One zero-day is confirmed as exploited in the wild. The release covers components including .NET, .NET Framework, Active Directory Certificate Services (AD CS), Azure services, and Windows. Tenable's count omits two CVEs assigned by MITRE, CVE-2026-6726 and CVE-2026-6727.

  • 398 CVEs patched: 42 critical, 355 important, 1 moderate
  • Three zero-days included; one exploited in the wild
  • Coverage spans .NET, AD CS, Azure, and Windows components
  • CVE-2026-68820 highlighted in the release
  • Two MITRE-assigned CVEs excluded from Tenable's count
OrganizationsTenable

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-6726
Info Leak in TCG TPM 2.0 Reference Code Enables Attestation Key Forgery

An information-leakage flaw in the Trusted Computing Group's TPM 2.0 reference code (tracked by TCG as VRT0010 and by CERT/CC as VU#431093) allows a local attacker with elevated privileges to obtain a credential from a TPM-aware certificate authority for a falsified TPM key. It is triggered locally on systems whose TPM runs code derived from the TCG reference implementation when the attacker manipulates key-attestation flows for keys such as an Attestation Key, DevID Key, or TLS authentication key. With the fraudulently issued credential, the attacker can falsify other TPM 2.0 attestations with that key, undermining device-identity and attestation guarantees. Any deployment of the TCG TPM 2.0 reference code - including commercial TPM chips, firmware TPMs, and TPM-aware CA/attestation infrastructure - is potentially affected; the available data does not specify version ranges. No exploitation has been observed: there is no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a ~0.2% chance of exploitation in the next 30 days.

Do: Track TCG VRT0010/VU#431093 and apply TPM/BIOS firmware updates from your PC or TPM vendor as they become available; Microsoft's August 2026 Patch Tuesday batch (398 CVEs) is among related releases, so verify whether your platform's TPM fix shipped there. Prioritize environments that use TPM key attestation with a CA (EK/AK, DevID, or TLS client certificates) and restrict local administrative privileges until patched. Audit attestation credentials issued by TPM-aware CAs for keys that may have been falsified.

7.9<1%
  • Trusted Computing Group (TCG) TPM 2.0 reference code (and TPM implementations derived from it)
masshundreds of millions of devices (TPM 2.0 is standard on modern PCs, and many TPM chips and firmware TPMs derive from the TCG reference code)
CVE-2026-6727
Timing Side-Channel in TCG TPM 2.0 Reference Code RSA-OAEP Decryption

CVE-2026-6727 is a timing side-channel vulnerability (CWE-208, tracked as TCGVRT0011) in the RSA OAEP decryption implementation of TPM 2.0 code derived from the Trusted Computing Group reference implementation. A privileged local attacker with access to the TPM command interface can measure timing differences across decryption operations to recover information sufficient to decrypt ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), import blobs, credential blobs, and session salts. Under certain conditions, the leaked information may also enable forgery of TPM 2.0 attestations, undermining trust in remote-attestation results. Any platform whose TPM 2.0 firmware is built from the affected TCG reference code is potentially affected, which spans TPM silicon from multiple vendors shipped across modern PCs, laptops, and servers; per-vendor exposure depends on whether the vulnerable code path was adopted. No public proof-of-concept or known exploitation exists (EPSS 0.2% over 30 days, not in CISA KEV).

Do: Inventory devices by TPM vendor/model and monitor for TPM firmware or driver fixes tied to TCGVRT0011 and VU#431093; apply updates from the device or silicon vendor as they are released, potentially surfacing through OS patch channels such as Microsoft's August 2026 Patch Tuesday. Until patched, restrict local privileged access to the TPM command interface to trusted code and weigh the risk of relying on TPM attestation for high-assurance operations. With no known exploitation and a high-complexity, local attack requirement, treat this as standard patch-cycle priority rather than an emergency.

5.9<1%
  • Trusted Computing Group TPM 2.0 reference code (TCGVRT0011 / VU#431093)
  • TPM 2.0 implementations built from the TCG reference code
mass≈100M+ devices (TPM 2.0 chips ship as standard in modern PCs, laptops, and servers; confirmed per-vendor counts unknown)
CVE-2026-68820
Use-After-Free Local Privilege Escalation in Microsoft Windows WinSock AFD Driver

CVE-2026-68820 is a use-after-free (CWE-416) in the Windows Ancillary Function Driver for WinSock (afd.sys), the kernel component that handles Winsock socket operations. A local, authenticated attacker can trigger the memory corruption through crafted socket activity, and the high attack-complexity score (AV:L/AC:H/PR:L) indicates exploitation requires a specific, likely race-sensitive sequence of operations. Successful exploitation elevates privileges to SYSTEM, giving the attacker full control of the host, and public reporting describes deployment of a backdoor after privilege escalation. Virtually every Windows 10, Windows 11, and Windows Server (2012-2022) installation ships this driver, so the affected population is essentially the entire supported Windows installed base. The flaw is being exploited in the wild: CISA added it to the KEV on 2026-08-11, Microsoft fixed it in the August 2026 Patch Tuesday release, and reporting ties active exploitation to North Korea's Lazarus group, who paired the zero-day with fake job-offer lures.

Do: Apply Microsoft's August 2026 security updates for all listed Windows 10, Windows 11, and Windows Server versions as a priority; CISA KEV (added 2026-08-11) requires federal agencies to patch within two weeks in accordance with BOD 26-04. Because observed attacks used fake job-offer social engineering to reach local code execution, prioritize user workstations and review endpoints for unexplained SYSTEM-level process activity, newly installed services, or backdoor persistence artifacts. Where patching is deferred, restrict execution of untrusted local code on affected hosts and monitor for privilege-escalation events.

7.06% KEV
  • Microsoft Windows Ancillary Function Driver for WinSock (afd.sys) as shipped with the Windows versions listed below
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • +1 more
masshundreds of millions to over 1 billion Windows devices and servers (essentially all endpoints running the listed Windows 10/11/Server versions)
Full article

42Critical 355Important 1Moderate 0Low Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild. Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727. This month’s update includes patches for: .NET .NET Core .NET Framework AMD Zen Active Directory Certificate Services (AD CS) Application Information Services Azure Active Directory Azure CycleCloud Azure Monitor Agent Azure Storage Explorer Capability Access Management Service (camsvc) Desktop Window…

This source does not provide full text. Read it at tenable.com.