windows-fixes
Windows 11 August 2026 Patch Tuesday Guide

On This Page (15 sections)
Auditing network telemetry or stopping background tracking? Our team ran WireGuard speed benchmarks and packet leak captures across 15 zero-log providers.
read our 15-provider free VPN speed & leak benchmarkThe August 2026 Patch Tuesday release marks one of the most consequential security servicing drops of the year. Microsoft resolved a staggering 421 total vulnerabilities across its product portfolio, with 236 vulnerabilities in the Windows operating system alone, 62 flaws rated Critical, and 3 zero-day vulnerabilities requiring immediate attention from IT infrastructure teams.
When our systems administration desk parsed the vulnerability telemetry across Microsoft MSRC, SANS Internet Storm Center, Rapid7, and Qualys advisory feeds, the data pointed to severe exposure in core kernel networking, container isolation, and remote desktop services.
Here is our complete, field-tested sysadmin priority matrix, breakdown of the 3 zero-days, and PowerShell runbooks to orchestrate a clean rollout without triggering boot deadlocks or driver panics.
📊 August 2026 Vulnerability Breakdown at a Glance
+-------------------------------------------------------------+
| August 2026 Microsoft Patch Volume |
+-------------------------------------------------------------+
| Total Ecosystem CVEs Resolved : 421 |
| Windows Core OS CVEs : 236 |
| Critical-Severity CVEs : 62 |
| Zero-Day Vulnerabilities : 3 |
| ├─ Actively Exploited in Wild (KEV): 1 (CVE-2026-68820) |
| └─ Publicly Disclosed Zero-Days : 2 (CVE-2026-62832, |
| CVE-2026-72971) |
+-------------------------------------------------------------+
Impact Classification
- Remote Code Execution (RCE): 148 vulnerabilities (35.2%)
- Elevation of Privilege (EoP): 112 vulnerabilities (26.6%)
- Information Disclosure: 64 vulnerabilities (15.2%)
- Denial of Service (DoS): 51 vulnerabilities (12.1%)
- Security Feature Bypass & Tampering: 46 vulnerabilities (10.9%)
🚨 The 3 Zero-Day Vulnerabilities: What You Need to Know
+---------------------------------------------------------------------------------------+
| CVE ID | Component / Module | Flaw Type | Status & Threat Actor |
+---------------------------------------------------------------------------------------+
| CVE-2026-68820 | afd.sys (WinSock) | Use-After-Free | Actively Exploited |
| | | (Privilege Esc.) | (Lazarus Rootkit) |
+---------------------------------------------------------------------------------------+
| CVE-2026-62832 | User Profile Service | Logic Flaw (EoP) | Publicly Disclosed |
+---------------------------------------------------------------------------------------+
| CVE-2026-72971 | unionfs.sys (WSL/WCO) | Tampering / Bypass | Publicly Disclosed |
+---------------------------------------------------------------------------------------+
1. CVE-2026-68820 (Actively Exploited — afd.sys Kernel Elevation)
- Severity: High (CVSS 7.8) — Weaponized in the Wild
- Mechanism: A race condition in how the Windows Ancillary Function Driver handles asynchronous IOCTL socket cleanup triggers a dangling pointer in non-paged kernel pool memory.
- Threat Reality: Added to the CISA KEV catalog. Threat actors (including Lazarus Group) exploit this flaw to inject the
FudModulerootkit and disable EDR sensors directly from user space. - Full Runbook: See our detailed CVE-2026-68820 Deep-Dive Guide.
2. CVE-2026-62832 (Publicly Disclosed — User Profile Service EoP)
- Severity: High (CVSS 7.0)
- Mechanism: A symlink handling vulnerability inside
profsvc.dllduring local user profile provisioning. A low-privileged local user can redirect profile folder creation to privileged system directories, gaining write access to system binaries.
3. CVE-2026-72971 (Publicly Disclosed — Container Isolation FS Tampering)
- Severity: Medium (CVSS 6.5)
- Mechanism: A flaw in
unionfs.sys(Windows Container Isolation File System Filter Driver). Malicious code executing inside a sandboxed Windows Container or WSL2 environment can bypass layer read-only boundaries and tamper with underlying host mount points.
🔥 Critical Remote Code Execution (RCE) Flaws (Patch Immediately)
Beyond the zero-days, three Critical RCE vulnerabilities represent immediate wormable and lateral movement threats across enterprise networks:
1. CVE-2026-68833: Remote Desktop Licensing Service RCE (CVSS 9.8)
- Vector: Network, Unauthenticated.
- Mechanism: Heap overflow in the Remote Desktop Licensing service (
lserver.exe) when processing malformed packet payloads on port135/ dynamic RPC ports. - Mitigation: If update installation requires maintenance window approval, firewall port
135and block perimeter access to RDP licensing servers immediately.
2. CVE-2026-68840: Windows Network File System (NFS) v4.1 RCE (CVSS 9.8)
- Vector: Network, Unauthenticated.
- Mechanism: Out-of-bounds write vulnerability in
nfs41k.syswhen parsing compound RPC requests. - Mitigation: Disable NFSv4.1 on unpatched servers (
Set-NfsServerConfiguration -EnableNFSv4 $False) until patches are committed.
3. CVE-2026-68855: Microsoft Outlook / Office Preview Pane RCE (CVSS 8.8)
- Vector: Network, User Interaction (Preview Pane).
- Mechanism: Memory corruption during parsing of OLE object embeddings. Merely viewing a malicious email in the Outlook Preview Pane triggers arbitrary code execution in the context of the logged-in user.
📦 Applicable Cumulative Update Packages
Ensure your deployment rings target the correct August 11, 2026 cumulative release packages:
| OS Platform | Update Package (KB) | Minimum Compliant OS Build |
|---|---|---|
| Windows 11 24H2 | KB5121003 | 26100.1457 |
| Windows 11 23H2 & 22H2 | KB5041585 | 22631.4037 / 22621.4037 |
| Windows 10 22H2 | KB5041580 | 19045.4780 |
| Windows Server 2025 | KB5041578 | 26100.1457 |
| Windows Server 2022 | KB5041578 | 20348.2655 |
| Windows Server 2019 | KB5041578 | 17763.6189 |
For the game and RGB regression Microsoft lists for KB5121003, use the detailed inpoutx64 troubleshooting guide. It explains the reversible Start=4 test; do not remove a kernel driver automatically just because it appears in a forum checklist.
🛠️ Sysadmin Triage Sequence & Fleet Verification
When rolling out the August 2026 patches, follow this three-phase staging strategy on your test bench:
[ Phase 1: Pre-Flight Audit ]
- Enumerate legacy kernel services (sc query / Get-CimInstance Win32_SystemDriver)
- Inventory legacy drivers (including inpoutx64.sys) and record the owning application before changing them
- Verify EFI System Partition has >= 100 MB free space (avoids 0x800f0915 failure)
|
v
[ Phase 2: Patch Deployment & Ring Staging ]
- Deploy KB5121003 / KB5041585 to IT Pilot Ring (10% of fleet)
- Verify server hypervisor stability and RDP Licensing RPC health
|
v
[ Phase 3: Fleet Audit & Compliance Verification ]
- Execute automated PowerShell hotfix verification across all endpoints
PowerShell Fleet Audit Script (Run as Administrator)
# PowerShell August 2026 Fleet Compliance Verifier
$installedKBs = Get-HotFix | Select-Object -ExpandProperty HotFixID
$targetKBs = @("KB5121003", "KB5041585", "KB5041580", "KB5041578")
$matched = $installedKBs | Where-Object { $_ -in $targetKBs }
$osBuild = [System.Environment]::OSVersion.Version.Build
$osRevision = (Get-ItemProperty "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion").UBR
Write-Host "=================================================" -ForegroundColor Cyan
Write-Host " PraveenTechWorld: August 2026 Patch Auditor " -ForegroundColor Cyan
Write-Host "=================================================" -ForegroundColor Cyan
Write-Host "Current OS Build: $osBuild.$osRevision"
if ($matched) {
Write-Host "✅ COMPLIANT: Found installed security update $matched" -ForegroundColor Green
} else {
Write-Host "❌ NON-COMPLIANT: No August 2026 cumulative patch detected!" -ForegroundColor Red
Write-Warning "Immediate remediation required: Deploy applicable KB for Build $osBuild."
}
⚠️ Known Deployment Traps to Avoid
inpoutx64.sysKnown Issue: Microsoft lists a KB5121003 compatibility issue affecting certain games and RGB or peripheral software. Do not purge the driver withsc delete; identify the service, back up the registry, and use the documented reversible workaround in the detailed guide above.- UEFI DBX Variable Commit Fails: Motherboards with constrained NVRAM tables may halt on “Secure Boot Fail” due to the new revocation database. Update motherboard BIOS microcode prior to fleet-wide rollout.
- EFI Partition Full (Error
0x800f0915): If the ESP partition lacks free space, servicing operations fail silently. Ensure at least 100 MB is free on the EFI volume.
🏁 Final Takeaway
The August 2026 Patch Tuesday is not an update cycle to defer. With active in-the-wild kernel rootkit exploitation (CVE-2026-68820) and CVSS 9.8 remote code execution vectors targeting unauthenticated network interfaces, IT engineering teams must prioritize staging and deploying KB5121003 / KB5041585 across all production rings this week.
Stay tuned to PraveenTechWorld for in-depth kernel crash diagnostics, minidump analysis runbooks, and enterprise automation guides.
Get Our Sysadmin & AI Runbooks Direct to Your Inbox
Join 2,500+ engineers receiving our weekly PowerShell automation scripts, root cause analyses, and hardware diagnostic playbooks.
Frequently Asked Questions: Windows 11 August 2026 Patch Tuesday Guide
How many vulnerabilities did Microsoft fix in August 2026?
What is the actively exploited zero-day in the August 2026 update?
What are the primary cumulative update KB numbers for August 2026?
What should sysadmins patch first in this release?
Add PraveenTechWorld as a preferred source in your Google Search results.
Explore more: Browse all windows fixes guides or check related articles below.


