Microsoft shipped fixes for 751 vulnerabilities across 67 update articles on August 11, 2026. It is a big number. It is not a record, and it is not the number that should decide your week.
One of the 751 is already being exploited. That is the story.
Start here: CVE-2026-68820
CVE-2026-68820 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock, better known as AFD.sys. CVSS 7.0, and Microsoft marks it Exploitation Detected, which is the label it uses when attacks are already happening rather than merely likely.
A CVSS of 7.0 looks unremarkable next to the Critical entries further down this release, and that is exactly why it gets underestimated. Elevation of privilege does not get an attacker onto a machine. It takes an attacker who is already there and makes them administrator. That is the second half of nearly every real intrusion: the phishing link or the exposed service gets the foothold, and a bug like this one turns the foothold into control. Drivers in the network stack keep appearing on exploited lists for the same reason, because they run in kernel context and every machine has them.
The fix ships in this month's cumulative updates. Depending on your build, that includes KB5120238, KB5120242, KB5120229 and KB5120249. Thirteen update articles carry the fix in total, so if your build is not one of those four, the CVE page lists the rest.
Two were public before the patch existed
Two further vulnerabilities were publicly disclosed before Microsoft shipped a fix, which means the details were available while everyone was still exposed. Neither is reported as being attacked.
- CVE-2026-62832, elevation of privilege in the Windows User Profile Service, CVSS 7.8. Microsoft rates it
Exploitation More Likely. It scores higher than the one under active attack and has the same shape: get in, then get up. - CVE-2026-72971, tampering in the Windows Container Isolation file system filter driver, CVSS 5.5. A narrower audience, mostly Windows container hosts.
Public plus unpatched is how a proof of concept becomes a campaign. Treat both as a shorter clock than the rest of the release, even without a confirmed attack.
108 Critical, and where they live
Microsoft rates 108 of the 751 as Critical. The interesting part is not the count but the location: CVE-2026-62827 in SharePoint Server, CVE-2026-62896 in Teams, and CVE-2026-62836 in Azure SQL Managed Instance are all Critical, and all three are elevation of privilege.
That is a pattern worth naming. Most organizations have a rhythm for patching Windows and nothing comparable for the collaboration and cloud services running alongside it. SharePoint in particular has been an entry point more than once this year, and the timing here is pointed: on the same day as this release, BleepingComputer reported that CISA had added an earlier Microsoft SharePoint flaw to its Known Exploited Vulnerabilities catalog after it was used in ransomware attacks. If your update process stops at the operating system, this is the month it shows.
What the number 751 actually contains
A headline count is only useful if you know what it counts, so here is the composition rather than just the total.
Microsoft's published Severity breakdown is 108 Critical, 396 Important, 207 Moderate and 32 Low. Those sum to 743, not 751, because 8 of the entries carry no Severity rating at all. Anyone presenting four numbers as a complete breakdown of 751 is quietly losing eight of them.
More significantly, 331 of the 751 are Azure Linux entries, which ship no Windows update article. So this is not 751 Windows fixes, and a count derived from update articles cannot see those entries at all. Senserva tracks 347 of the 751 against update articles we hold pages for, which is why you will see both figures on our Patch Tuesday page, each labeled. Microsoft's 751 is the number this release is known by, and we lead with it. Our 347 is the number that maps to updates you can actually deploy.
What to do this week
- The exploited one first. AFD.sys, this month's cumulative update, today rather than at the weekend.
- The two disclosed ones next, because public details plus no patch is the shortest path from research to attack.
- Look past Windows. SharePoint, Teams and Azure SQL Managed Instance appear in this release and rarely share a maintenance window with the servers.
- Know what you actually run. 751 fixes only matter to the extent they land on machines you own. Patch Tuesday is when a good many organizations discover their inventory was an estimate.
Every CVE and every update article named above has its own page on senserva.com, with the affected products, the known issues in Microsoft's own words, and the change trail as Microsoft revises entries through the month. The patch tracker ranks this month's updates by real-world risk rather than by Severity label alone.
Get told when this changes, free
The hardest part of a release this size is not today. It is the next three weeks, when Microsoft revises entries, CISA adds things to its Known Exploited Vulnerabilities catalog, and a CVE that looked routine on Tuesday turns out to be under attack by Friday. That is exactly what happened to the SharePoint flaw above.
Senserva Watch tells you when it changes. It is free, it takes one email address, and it covers the CVEs and updates you care about: a KEV addition, a revised advisory, a new known issue on an update you deployed. Members also get the Patch Tuesday wire on release day, three free unlimited audits of the whole Microsoft 365 estate, a fresh audit credit each quarter, and 20% off a purchase. Join Senserva Watch.
Sources
- Microsoft Security Response Center, August 2026 Security Updates. The primary source for every figure above, read from the CVRF release data on release day.
- Microsoft, KB5120238 release notes, one of the cumulative updates carrying the AFD.sys fix.
- BleepingComputer, "CISA: Microsoft SharePoint flaw now exploited in ransomware attacks", August 11, 2026.
Written by Senserva Trustworthy AI from Microsoft's own release data, validated so every CVE and update article named resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Figures as of August 11, 2026.
Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.