As cited
Copy frozen at (site build).
vulnerabilities
Microsoft Plugs Nearly 400 Security Holes
Microsoft released fixes for 398 security vulnerabilities across Windows and supported software in August, including one actively exploited zero-day (CVE-2026-68820) in the afd.sys driver and two previously disclosed flaws. The patch volume continues a trend driven by artificial intelligence-assisted vulnerability discovery, with 42 flaws rated critical. Security experts caution that while patching must continue, organizations should test thoroughly before deployment rather than rushing updates, and that AI-generated patches require human validation since they fail or introduce new weaknesses more than half the time.
Why it matters: Windows administrators must prioritize CVE-2026-68820 (afd.sys privilege escalation) as it is actively exploited, but should stagger deployment of the full 398-patch bundle across test environments first to avoid production disruptions and allow time for any regressions to surface.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Microsoft Plugs Nearly 400 Security Holes
Microsoft released fixes for 398 security vulnerabilities across Windows and supported software in August, including one actively exploited zero-day (CVE-2026-68820) in the afd.sys driver and two previously disclosed flaws. The patch volume continues a trend driven by artificial intelligence-assisted vulnerability discovery, with 42 flaws rated critical. Security experts caution that while patching must continue, organizations should test thoroughly before deployment rather than rushing updates, and that AI-generated patches require human validation since they fail or introduce new weaknesses more than half the time.
Why it matters: Windows administrators must prioritize CVE-2026-68820 (afd.sys privilege escalation) as it is actively exploited, but should stagger deployment of the full 398-patch bundle across test environments first to avoid production disruptions and allow time for any regressions to surface.
- Source published
- First seen by Cybersecurity Tracker