CYBERSECURITYTRACKER
TRACKING7,665 stories in this site build1,646 vulnerability news stories in this site build
Permanent story citation

Microsoft Plugs Nearly 400 Security Holes

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4257

As cited

Copy frozen at (site build).

vulnerabilities

Microsoft Plugs Nearly 400 Security Holes

Microsoft released fixes for 398 security vulnerabilities across Windows and supported software in August, including one actively exploited zero-day (CVE-2026-68820) in the afd.sys driver and two previously disclosed flaws. The patch volume continues a trend driven by artificial intelligence-assisted vulnerability discovery, with 42 flaws rated critical. Security experts caution that while patching must continue, organizations should test thoroughly before deployment rather than rushing updates, and that AI-generated patches require human validation since they fail or introduce new weaknesses more than half the time.

Why it matters: Windows administrators must prioritize CVE-2026-68820 (afd.sys privilege escalation) as it is actively exploited, but should stagger deployment of the full 398-patch bundle across test environments first to avoid production disruptions and allow time for any regressions to surface.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Microsoft Plugs Nearly 400 Security Holes

Microsoft released fixes for 398 security vulnerabilities across Windows and supported software in August, including one actively exploited zero-day (CVE-2026-68820) in the afd.sys driver and two previously disclosed flaws. The patch volume continues a trend driven by artificial intelligence-assisted vulnerability discovery, with 42 flaws rated critical. Security experts caution that while patching must continue, organizations should test thoroughly before deployment rather than rushing updates, and that AI-generated patches require human validation since they fail or introduce new weaknesses more than half the time.

Why it matters: Windows administrators must prioritize CVE-2026-68820 (afd.sys privilege escalation) as it is actively exploited, but should stagger deployment of the full 398-patch bundle across test environments first to avoid production disruptions and allow time for any regressions to surface.

VendorsMicrosoftGoogleCiscoOracleAdobe
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary