Part of our windows fixes guide series

windows-fixes

Windows 11 August 2026 Patch Tuesday Guide

Praveen7 min read
Minimal flat editorial illustration of a desk calendar page with a security shield and highlighted amber patch date
On This Page (15 sections)
Workbench Security Audit

Auditing network telemetry or stopping background tracking? Our team ran WireGuard speed benchmarks and packet leak captures across 15 zero-log providers.

read our 15-provider free VPN speed & leak benchmark

The August 2026 Patch Tuesday release marks one of the most consequential security servicing drops of the year. Microsoft resolved a staggering 421 total vulnerabilities across its product portfolio, with 236 vulnerabilities in the Windows operating system alone, 62 flaws rated Critical, and 3 zero-day vulnerabilities requiring immediate attention from IT infrastructure teams.

When our systems administration desk parsed the vulnerability telemetry across Microsoft MSRC, SANS Internet Storm Center, Rapid7, and Qualys advisory feeds, the data pointed to severe exposure in core kernel networking, container isolation, and remote desktop services.

Here is our complete, field-tested sysadmin priority matrix, breakdown of the 3 zero-days, and PowerShell runbooks to orchestrate a clean rollout without triggering boot deadlocks or driver panics.


📊 August 2026 Vulnerability Breakdown at a Glance

+-------------------------------------------------------------+
|               August 2026 Microsoft Patch Volume            |
+-------------------------------------------------------------+
| Total Ecosystem CVEs Resolved        : 421                  |
| Windows Core OS CVEs                 : 236                  |
| Critical-Severity CVEs               : 62                   |
| Zero-Day Vulnerabilities             : 3                    |
|   ├─ Actively Exploited in Wild (KEV): 1 (CVE-2026-68820)   |
|   └─ Publicly Disclosed Zero-Days    : 2 (CVE-2026-62832,   |
|                                           CVE-2026-72971)   |
+-------------------------------------------------------------+

Impact Classification

  • Remote Code Execution (RCE): 148 vulnerabilities (35.2%)
  • Elevation of Privilege (EoP): 112 vulnerabilities (26.6%)
  • Information Disclosure: 64 vulnerabilities (15.2%)
  • Denial of Service (DoS): 51 vulnerabilities (12.1%)
  • Security Feature Bypass & Tampering: 46 vulnerabilities (10.9%)

🚨 The 3 Zero-Day Vulnerabilities: What You Need to Know

+---------------------------------------------------------------------------------------+
| CVE ID         | Component / Module    | Flaw Type           | Status & Threat Actor  |
+---------------------------------------------------------------------------------------+
| CVE-2026-68820 | afd.sys (WinSock)     | Use-After-Free      | Actively Exploited     |
|                |                       | (Privilege Esc.)    | (Lazarus Rootkit)      |
+---------------------------------------------------------------------------------------+
| CVE-2026-62832 | User Profile Service  | Logic Flaw (EoP)    | Publicly Disclosed     |
+---------------------------------------------------------------------------------------+
| CVE-2026-72971 | unionfs.sys (WSL/WCO) | Tampering / Bypass  | Publicly Disclosed     |
+---------------------------------------------------------------------------------------+

1. CVE-2026-68820 (Actively Exploited — afd.sys Kernel Elevation)

  • Severity: High (CVSS 7.8) — Weaponized in the Wild
  • Mechanism: A race condition in how the Windows Ancillary Function Driver handles asynchronous IOCTL socket cleanup triggers a dangling pointer in non-paged kernel pool memory.
  • Threat Reality: Added to the CISA KEV catalog. Threat actors (including Lazarus Group) exploit this flaw to inject the FudModule rootkit and disable EDR sensors directly from user space.
  • Full Runbook: See our detailed CVE-2026-68820 Deep-Dive Guide.

2. CVE-2026-62832 (Publicly Disclosed — User Profile Service EoP)

  • Severity: High (CVSS 7.0)
  • Mechanism: A symlink handling vulnerability inside profsvc.dll during local user profile provisioning. A low-privileged local user can redirect profile folder creation to privileged system directories, gaining write access to system binaries.

3. CVE-2026-72971 (Publicly Disclosed — Container Isolation FS Tampering)

  • Severity: Medium (CVSS 6.5)
  • Mechanism: A flaw in unionfs.sys (Windows Container Isolation File System Filter Driver). Malicious code executing inside a sandboxed Windows Container or WSL2 environment can bypass layer read-only boundaries and tamper with underlying host mount points.

🔥 Critical Remote Code Execution (RCE) Flaws (Patch Immediately)

Beyond the zero-days, three Critical RCE vulnerabilities represent immediate wormable and lateral movement threats across enterprise networks:

1. CVE-2026-68833: Remote Desktop Licensing Service RCE (CVSS 9.8)

  • Vector: Network, Unauthenticated.
  • Mechanism: Heap overflow in the Remote Desktop Licensing service (lserver.exe) when processing malformed packet payloads on port 135 / dynamic RPC ports.
  • Mitigation: If update installation requires maintenance window approval, firewall port 135 and block perimeter access to RDP licensing servers immediately.

2. CVE-2026-68840: Windows Network File System (NFS) v4.1 RCE (CVSS 9.8)

  • Vector: Network, Unauthenticated.
  • Mechanism: Out-of-bounds write vulnerability in nfs41k.sys when parsing compound RPC requests.
  • Mitigation: Disable NFSv4.1 on unpatched servers (Set-NfsServerConfiguration -EnableNFSv4 $False) until patches are committed.

3. CVE-2026-68855: Microsoft Outlook / Office Preview Pane RCE (CVSS 8.8)

  • Vector: Network, User Interaction (Preview Pane).
  • Mechanism: Memory corruption during parsing of OLE object embeddings. Merely viewing a malicious email in the Outlook Preview Pane triggers arbitrary code execution in the context of the logged-in user.

📦 Applicable Cumulative Update Packages

Ensure your deployment rings target the correct August 11, 2026 cumulative release packages:

OS PlatformUpdate Package (KB)Minimum Compliant OS Build
Windows 11 24H2KB512100326100.1457
Windows 11 23H2 & 22H2KB504158522631.4037 / 22621.4037
Windows 10 22H2KB504158019045.4780
Windows Server 2025KB504157826100.1457
Windows Server 2022KB504157820348.2655
Windows Server 2019KB504157817763.6189

For the game and RGB regression Microsoft lists for KB5121003, use the detailed inpoutx64 troubleshooting guide. It explains the reversible Start=4 test; do not remove a kernel driver automatically just because it appears in a forum checklist.


🛠️ Sysadmin Triage Sequence & Fleet Verification

When rolling out the August 2026 patches, follow this three-phase staging strategy on your test bench:

[ Phase 1: Pre-Flight Audit ]
  - Enumerate legacy kernel services (sc query / Get-CimInstance Win32_SystemDriver)
  - Inventory legacy drivers (including inpoutx64.sys) and record the owning application before changing them
  - Verify EFI System Partition has >= 100 MB free space (avoids 0x800f0915 failure)
               |
               v
[ Phase 2: Patch Deployment & Ring Staging ]
  - Deploy KB5121003 / KB5041585 to IT Pilot Ring (10% of fleet)
  - Verify server hypervisor stability and RDP Licensing RPC health
               |
               v
[ Phase 3: Fleet Audit & Compliance Verification ]
  - Execute automated PowerShell hotfix verification across all endpoints

PowerShell Fleet Audit Script (Run as Administrator)

# PowerShell August 2026 Fleet Compliance Verifier
$installedKBs = Get-HotFix | Select-Object -ExpandProperty HotFixID
$targetKBs = @("KB5121003", "KB5041585", "KB5041580", "KB5041578")
$matched = $installedKBs | Where-Object { $_ -in $targetKBs }

$osBuild = [System.Environment]::OSVersion.Version.Build
$osRevision = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").UBR

Write-Host "=================================================" -ForegroundColor Cyan
Write-Host "   PraveenTechWorld: August 2026 Patch Auditor   " -ForegroundColor Cyan
Write-Host "=================================================" -ForegroundColor Cyan
Write-Host "Current OS Build: $osBuild.$osRevision"

if ($matched) {
    Write-Host "✅ COMPLIANT: Found installed security update $matched" -ForegroundColor Green
} else {
    Write-Host "❌ NON-COMPLIANT: No August 2026 cumulative patch detected!" -ForegroundColor Red
    Write-Warning "Immediate remediation required: Deploy applicable KB for Build $osBuild."
}

⚠️ Known Deployment Traps to Avoid

  1. inpoutx64.sys Known Issue: Microsoft lists a KB5121003 compatibility issue affecting certain games and RGB or peripheral software. Do not purge the driver with sc delete; identify the service, back up the registry, and use the documented reversible workaround in the detailed guide above.
  2. UEFI DBX Variable Commit Fails: Motherboards with constrained NVRAM tables may halt on “Secure Boot Fail” due to the new revocation database. Update motherboard BIOS microcode prior to fleet-wide rollout.
  3. EFI Partition Full (Error 0x800f0915): If the ESP partition lacks free space, servicing operations fail silently. Ensure at least 100 MB is free on the EFI volume.

🏁 Final Takeaway

The August 2026 Patch Tuesday is not an update cycle to defer. With active in-the-wild kernel rootkit exploitation (CVE-2026-68820) and CVSS 9.8 remote code execution vectors targeting unauthenticated network interfaces, IT engineering teams must prioritize staging and deploying KB5121003 / KB5041585 across all production rings this week.

Stay tuned to PraveenTechWorld for in-depth kernel crash diagnostics, minidump analysis runbooks, and enterprise automation guides.

Hardware & RepairSponsored Diagnostic Tools
Free PowerShell & Sysadmin Toolkit

Get Our Sysadmin & AI Runbooks Direct to Your Inbox

Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.

Zero spam. Unsubscribe anytime in 1 click.

Frequently Asked Questions: Windows 11 August 2026 Patch Tuesday Guide

How many vulnerabilities did Microsoft fix in August 2026?
Microsoft resolved 421 total vulnerabilities across the ecosystem, including 236 distinct flaws in the Windows core OS, 62 rated Critical, and 3 zero-days (1 actively exploited in the wild and 2 publicly disclosed).
What is the actively exploited zero-day in the August 2026 update?
The actively weaponized bug is CVE-2026-68820, a Use-After-Free (UAF) flaw in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows local privilege escalation to NT AUTHORITY\SYSTEM.
What are the primary cumulative update KB numbers for August 2026?
The primary updates are KB5121003 for Windows 11 24H2, KB5041585 for Windows 11 23H2/22H2, KB5041580 for Windows 10 22H2, and KB5041578 for Windows Server 2022/2025.
What should sysadmins patch first in this release?
Prioritize endpoints running unauthenticated network services (RDP Licensing, NFS v4.1) and immediately deploy KB5121003/KB5041585 to neutralize the afd.sys kernel rootkit vector.
Get Independent Tech Benchmarks First

Add PraveenTechWorld as a preferred source in your Google Search results.

Prefer on Google
P
Praveen

IT ops lead in India. I break Windows, Android and self-hosted AI stacks on my workbench, then write down what actually fixed them.

Explore more: Browse all windows fixes guides or check related articles below.