Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock (CVE-2026-68820), which, according to Todd Schell, principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges. “Exploitation has already been detected,” noted Jack Bicer, director of vulnerability research at Action1, “making this the highest priority vulnerability in this month’s release.” Separately, SAP issued 29 new and updated security patches, the most severe of which is CVE-2026-58231, with a CVSS score of 10. This is an improper authorization issue in SAP Commerce Cloud’s Data Hub Adapter. 42 critical Microsoft vulnerabilities In total, Microsoft addressed 398 CVEs. Of them, 42 were rated critical, while 355 were rated Important. However, Tyler Reguly, associate director of security R&D at Fortra, noted that 236 CVEs affect Windows and are covered by a cumulative update. Another 98 are Office CVEs that are covered by separate Office cumulative updates, unless you happen to still run Office 2016 In addition to the actively exploited zero-day, Microsoft also warned of two other zero-days. CVE-2026-62832 is an elevation of privilege vulnerability in the Windows User Profile Service, rated Important. Action1 pointed out this has been publicly disclosed, so exploitation is likely; Ivanti noted that it is the flaw behind “LegacyHive,” the unpatched proof-of-concept released by researcher Nightmare-Eclipse just hours after July’s Patch Tuesday. This vulnerability lets a standard user coerce the User Profile Service into loading another user’s registry hive, even an administrator’s, to gain unauthorized access to that CVEs: CVE-2026-68820, CVE-2026-58231, CVE-2026-62832, CVE-2026-72971, CVE-2024-38193. CISA KEV/exploitation signal detected. Vendors: Microsoft, Tenable, Oracle, SAP, Adobe, Ivanti, GitHub. DORA relevance: high.