🔴 Critical  |  Source: Krebs on Security


Microsoft’s August 2026 Patch Tuesday addresses 398 security vulnerabilities across Windows and related software — one of the largest single patch releases on record. One vulnerability is actively being exploited in the wild, whilst two others were publicly disclosed before patches were available, increasing the risk of targeted attacks. Organisations running Microsoft products should treat this release as urgent.

Security Architect’s Take: Prioritise patching the actively exploited vulnerability and the two publicly disclosed flaws immediately — identify affected assets across cloud-hosted Windows workloads (Azure VMs, AVD, hybrid AD-joined machines) and push emergency patching cycles. Review your Defender for Cloud secure score and Update Manager compliance dashboards to assess exposure at scale before threat actors weaponise the remaining CVEs.

Original advisory: Microsoft Plugs Nearly 400 Security Holes