On August 11, 2026, Microsoft released a series of updates designed to fix a total of 398 security vulnerabilities in its Windows operating systems and other associated software. The package includes the solution to a flaw that is already being actively exploited by malicious actors, as well as two others that had their details publicly revealed before official release.
The volume of fixes released by Microsoft this August, although significant, did not surpass the record set in July, when more than 570 updates were made available. However, it represents double the number of patches in June, which totaled almost 200. The company attributes this increase in the number of fixes to the effectiveness of artificial intelligence in detecting vulnerabilities, indicating that Windows users should get used to “Update Tuesdays”, which occur on the second Tuesday of each month and address hundreds of new flaws.
Among the 398 vulnerabilities fixed, 42 were classified as “critical”, meaning they are extremely serious flaws. Cyberattacks or individuals with malicious intent could exploit them to take remote control of a Windows computer, often with minimal or no user interaction.
More on this story: Urgent Chrome update fixes security holes that allow remote control of the system
The only known “zero-day” flaw, which was already being explored, fixed by Microsoft this month is CVE-2026-68820. This is a privilege escalation vulnerability located in afd.sys, an essential component of Windows. Security company Automox describes afd.sys as the “driver that manages Windows socket connections on virtually all devices.”
Automox’s Landon Miles explained in a blog about the updates that this flaw does not serve as an initial entry point. He described the exploit as a secondary step: an attacker first gains access to a system with low privileges, usually through phishing, and then uses the driver vulnerability to take full control. Despite the complexity of the attack, which requires multiple executions to coincide with the right moment, the flaw is being effectively exploited.
Learn more: Microsoft Amplifies Windows Updates Against AI-Driven Vulnerability Threats
Another privilege escalation vulnerability, CVE-2026-62832, was also classified by Microsoft as likely exploitable. This flaw, which affects the Windows User Profile Service, may be linked to a recent public disclosure known as “LegacyHive” by security expert Nightmare Eclipse. A third flaw, CVE-2026-72971, is a lower-impact local tampering vulnerability that Microsoft considers unlikely to be exploited.
Large software companies across the industry are also stepping up the frequency and volume of their updates, driven by the use of artificial intelligence. Adobe, for example, started issuing security bulletins twice a month last month. Other companies such as Cisco, Google, Mozilla and Oracle are also releasing a greater number of patches more regularly.
Artificial intelligence demonstrates remarkable efficiency in identifying security flaws in software. However, the task of fixing the vast number of discovered bugs still requires a heavy reliance on human intervention. It remains uncertain whether AI technologies will prove to be as effective in patching vulnerabilities as they are in discovering and exploiting them, especially considering that these same AIs already suggest solutions for the holes they find.
Researchers at 1Password conducted a recent study on the performance of different large language models (LLMs) when generating fixes for newly identified complex vulnerabilities. The results revealed that, in more than half of the cases, LLMs produced solutions that were ineffective or introduced new vulnerabilities, or both problems simultaneously.
On the same topic: Google launches Gemini 3.5 Flash Cyber, a lightweight AI model to strengthen global cybersecurity
Ed Skoudis, president of the SANS Technology Institute, commented that his team has achieved excellent results when using artificial intelligence to create patches, as long as there is human involvement to test the proposed solutions and make continuous improvements.
Skoudis wrote in a SANS newsletter that AI is becoming incredibly proficient at identifying vulnerabilities, but research shows that fixing these flaws is a very distinct challenge. He advises not to expect AI patching to work reliably all at once. Instead, it suggests an iterative process of testing, questioning, improving, and checking. AI can be an exceptional ally in fixing problems, but it still requires a human expert in control.
Fortra’s Tyler Reguly noted that while news of the hundreds of vulnerabilities patched by Microsoft may prompt some organizations to try to speed up their patching processes, it’s critical to remember that only one of the nearly 400 flaws patched this cycle is under active exploitation. Reguly advised security leaders to talk to their teams to understand how they are managing the increased workload, which commonly involves testing patches before deploying them to production environments.
Reguly advised security directors to talk to their teams about adapting their workflows to adjust to the new pace of updates. He emphasized the importance of supporting teams across organizational units, enabling the changes they deem necessary. According to him, there is no need to rush these updates, regardless of pressure from suppliers and other organizations. The essential thing is to ensure that the updates implemented are safe and do not cause negative impacts on the systems.
Finally, when considering software updates, you must not forget to back up your system and data before applying this month’s substantial update package. The day after “Patch Tuesday” is ironically called “Reboot Wednesday”, but in general, it is acceptable to wait a few days to install these large update packages, as Microsoft sometimes takes time to fix any problems that arise after the initial patches.

