Microsofts August 2026 Patch Tuesday addresses 94 security vulnerabilities across Windows, Office, Azure, and other products. Three of the patched vulnerabilities are confirmed zero-days actively exploited in the wild.
Critical Zero-Days
- CVE-2026-38178 (CVSS 9.1) — Windows SmartScreen bypass allowing arbitrary code execution via crafted .url files. Actively exploited by APT28.
- CVE-2026-38195 (CVSS 8.8) — Windows Kernel elevation of privilege via race condition in NTFS driver.
- CVE-2026-38201 (CVSS 8.1) — Microsoft Outlook RCE through crafted email messages. No user interaction required.
Recommendations
Organizations should prioritize patching the three zero-days immediately. Full details available in the Microsoft Security Response Center advisory.