A heap of overflow in August’s Patch Tuesday haul

Imported from official source

Cybersecurity Classified by Officially

421 CVEs, a relatively small set of Edge patches, and two spicy stragglers

Microsoft on August 11 released 421 patches affecting 29 product families. Sixty-four of the addressed issues are considered by Microsoft to be of Critical severity; 35 CVEs are expected to be exploited within the next 30 days. (One already is; CVE-2026-68820 is an Important-severity Elevation of Privilege issue affecting most versions of Windows.) Eighty have a CVSS Base score of 8.0 or higher. Just one was publicly disclosed (but not yet exploited) as of release day, with one additional item (CVE-2026-69414) stated by Microsoft to be publicly disclosed by week’s end. (More on post-Tuesday patch activity in a moment.) One other, CVE-2026-68820, is acknowledged to be under active exploit in the wild. 

In this AI-driven era, the relatively low count of advisories is striking. There are two MITRE-credited items (CVE-2026-6726, CVE-2026-6727) that were patched earlier in the month, but as these are Windows-related we’re simply rolling them into the main patch count. As for Edge, there were just 42 advisories (all but two issued by Chrome, not Microsoft), with everything patched in advance of Tuesday. There were also 24 updates issued by Adobe, affecting Commerce and ColdFusion.

Of greater interest is the remarkable number of very nasty bugs that were also patched earlier in the month. Nineteen vulnerabilities affecting 10 families have already been mitigated, and a twentieth (CVE-2026-24301, a Copilot Web issue) was handled several days later. The average CVSS Base score for those 20 is 9.3, with three weighing in at a “perfect” 10. In contrast, the average CVSS Base score for the rest of August’s patches is a less agita-inducing 7.2.

Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in the usual table below. 

This is an extract. The publication continues at the source.

Read the original at the source: https://www.sophos.com/en-gb/blog/2608-patch-tuesday

Officially imported this from Sophos’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Sophos — imported from official source
Official source
https://news.sophos.com/feed/ RSS
Imported
September 23, 2026 21:00
Versions
1 recorded
Identity
blt1e27c2b7d9d50537

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.