August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Summary

Microsoft's August 2026 Patch Tuesday addresses a significant number of vulnerabilities, including 421 CVEs. Among these is a critical use-after-free flaw in the afd.sys Windows kernel-mode driver, which has already been exploited in the wild to achieve SYSTEM privileges.

IFF Assessment

FOE

The exploitation of a zero-day vulnerability in a core Windows component represents a significant threat to users and organizations.

Severity

9.0 Critical (AI Estimated)

A use-after-free vulnerability in a kernel-mode driver that allows for SYSTEM privilege escalation is highly critical, with a high attack vector and significant impact.

Defender Context

This Patch Tuesday highlights the ongoing importance of timely patching, especially for critical zero-day vulnerabilities that are actively exploited. Defenders should prioritize updates for Windows systems and monitor for indicators of compromise related to the afd.sys driver.

Read Full Story →