{
 "provider": "Senserva",
 "note": "Every mass alert emailed to Senserva Watch members: when it went out, the CVEs and KBs it named, and the text. What was sent, never to whom.",
 "updated": "2026-08-11T21:13:54.943Z",
 "count": 3,
 "alerts": [
  {
   "at": "2026-08-11T20:13:34.204Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": false
    },
    {
     "id": "CVE-2026-62832",
     "page": false
    },
    {
     "id": "CVE-2026-72971",
     "page": false
    }
   ],
   "kbs": [
    {
     "id": "KB5120238",
     "page": false
    },
    {
     "id": "KB5120242",
     "page": false
    },
    {
     "id": "KB5120229",
     "page": false
    },
    {
     "id": "KB5120249",
     "page": false
    }
   ],
   "text": "August 2026\n\nMicrosoft shipped fixes for 751 vulnerabilities across 67 update articles.\n\nOne of them is already being exploited: CVE-2026-68820, the Windows Ancillary Function Driver for WinSock (AFD.sys). Elevation of privilege, CVSS 7.0, and Microsoft marks it Exploitation Detected.  It does not get an attacker onto a machine; it takes an attacker who is already there and makes them administrator.\n\nThe fix ships in this month's cumulative updates. Depending on your build: KB5120238, KB5120242, KB5120229, KB5120249. Thirteen updates carry it in total, so if your build is not in that list, check the CVE page:  https://senserva.com/cve/CVE-2026-68820.html\n\nEvery KB in this release, all 67, with what each one fixes: https://senserva.com/patch-tuesday.html\n\nPUBLIC BEFORE THE PATCH\n\nTwo more were publicly disclosed before a fix existed. Neither is confirmed as being attacked, but the details were out while everyone was exposed.\n\nCVE-2026-62832, Windows User Profile Service, elevation of privilege, CVSS 7.8. Microsoft rates it Exploitation More Likely, and it scores higher than the one under active attack. https://senserva.com/cve/CVE-2026-62832.html\n\nCVE-2026-72971, Windows Container Isolation file system filter driver, tampering, CVSS 5.5. Narrower: mostly Windows container hosts. https://senserva.com/cve/CVE-2026-72971.html\n\nTHE SHAPE OF THE MONTH\n\n108 of the 751 are rated Critical by Microsoft. The Severity split covers 743 of them (108 Critical, 396 Important, 207 Moderate, 32 Low); the remaining 8 carry no rating at all.\n\nWorth noting where the Critical ones live. SharePoint Server, Teams and Azure SQL Managed Instance all appear, all elevation of privilege. Most patching routines have a rhythm for Windows and nothing like it for the collaboration and cloud services sitting alongside.\n\nTHREE THINGS THIS WEEK\n\n1. The exploited one first: AFD.sys, this month's cumulative update, today.\n\n2. The two public ones next. Public plus unpatched is how a proof of concept becomes a campaign.\n\n3. Look past Windows. SharePoint, Teams and Azure SQL rarely share a maintenance window with the servers.\n\nEvery CVE and every KB above has its own page on senserva.com, with the  affected products, the known issues in Microsoft's own words, and the change trail as Microsoft revises through the month.\n\nTrack it as Microsoft revises through the month: https://senserva.com/microsoft-patch-tracker.html\n\nWHERE THESE NUMBERS COME FROM\n\nEvery figure above is Microsoft's own, from the Security Response Center's CVRF 2026-Aug release document, read directly on release day. Senserva tracks 347 of the 751 against update articles we hold pages for, and the difference is largely Azure Linux entries that ship no KB article, so you will see both numbers on the site, labeled."
  },
  {
   "at": "2026-08-11T19:46:58.235Z",
   "cves": [
    {
     "id": "CVE-2026-68820",
     "page": false
    },
    {
     "id": "CVE-2026-62832",
     "page": false
    },
    {
     "id": "CVE-2026-72971",
     "page": false
    }
   ],
   "kbs": [
    {
     "id": "KB5120238",
     "page": false
    },
    {
     "id": "KB5120242",
     "page": false
    },
    {
     "id": "KB5120229",
     "page": false
    },
    {
     "id": "KB5120249",
     "page": false
    }
   ],
   "text": "August 2026, and the number that matters is not 751.\n\nMicrosoft shipped fixes for 751 vulnerabilities across 67 update articles.\nOne of them is already being exploited.\n\nSTART HERE\nCVE-2026-68820, the Windows Ancillary Function Driver for WinSock (AFD.sys).\nElevation of privilege, CVSS 7.0, and Microsoft marks it Exploitation\nDetected. It does not get an attacker onto a machine; it takes an attacker\nwho is already there and makes them administrator.\n\nThe fix ships in this month's cumulative updates. Depending on your build:\nKB5120238, KB5120242, KB5120229, KB5120249. Thirteen updates carry it in\ntotal, so if your build is not in that list, check the CVE page:\nhttps://senserva.com/cve/CVE-2026-68820.html\n\nEvery KB in this release, all 67, with what each one fixes:\nhttps://senserva.com/patch-tuesday.html\n\nPUBLIC BEFORE THE PATCH\nTwo more were publicly disclosed before a fix existed. Neither is confirmed\nas being attacked, but the details were out while everyone was exposed.\n\nCVE-2026-62832, Windows User Profile Service, elevation of privilege,\nCVSS 7.8. Microsoft rates it Exploitation More Likely, and it scores higher\nthan the one under active attack.\nhttps://senserva.com/cve/CVE-2026-62832.html\n\nCVE-2026-72971, Windows Container Isolation file system filter driver,\ntampering, CVSS 5.5. Narrower: mostly Windows container hosts.\nhttps://senserva.com/cve/CVE-2026-72971.html\n\nTHE SHAPE OF THE MONTH\n108 of the 751 are rated Critical by Microsoft. The Severity split covers 743\nof them (108 Critical, 396 Important, 207 Moderate, 32 Low); the remaining 8\ncarry no rating at all.\n\nWorth noting where the Critical ones live. SharePoint Server, Teams and Azure\nSQL Managed Instance all appear, all elevation of privilege. Most patching\nroutines have a rhythm for Windows and nothing like it for the collaboration\nand cloud services sitting alongside.\n\nTHREE THINGS THIS WEEK\n1. The exploited one first: AFD.sys, this month's cumulative update, today.\n2. The two public ones next. Public plus unpatched is how a proof of concept\n   becomes a campaign.\n3. Look past Windows. SharePoint, Teams and Azure SQL rarely share a\n   maintenance window with the servers.\n\nEvery CVE and every KB above has its own page on senserva.com, with the\naffected products, the known issues in Microsoft's own words, and the change\ntrail as Microsoft revises through the month.\n\nTrack it as Microsoft revises through the month:\nhttps://senserva.com/microsoft-patch-tracker.html\n\nSource: Microsoft Security Response Center, CVRF 2026-Aug, read on release\nday. Figures are Microsoft's own."
  },
  {
   "at": "2026-08-11T19:46:18.956Z",
   "cves": [
    {
     "id": "CVE-2026-8037",
     "page": false
    }
   ],
   "kbs": [],
   "text": "Progress LoadMaster Command Injection Vulnerability (CVE-2026-8037) is the CVE to watch right now. The Progress LoadMaster flaw is rated Critical with a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-07, which means it is being attacked in the wild, not just in theory. If it is in your environment, patch it now. Details, affected versions, and remediation guidance: https://senserva.com/cve/CVE-2026-8037.html"
  }
 ]
}
