Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 4

Imported from official source

Cybersecurity Classified by Officially

Serial Number: AV26-804
Date: August 11, 2026
Updated:September 25, 2026

As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products:

  • Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2
  • Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2
  • Microsoft Dynamics 365 Business Central 2024
  • Microsoft Dynamics 365 Business Central 2026
  • Microsoft Dynamics 365 Business Central Release Wave 1 2025
  • Microsoft Dynamics 365 Business Central Release Wave 2 2025
  • Microsoft Exchange Server Subscription Edition RTM
  • Microsoft Planetary Computer Pro (GeoCatalog)
  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server Subscription Edition
  • Microsoft Visual Studio Code CoPilot Chat Extension
  • The Cyber Centre encourages users and administrators to review the web link provided, perform the suggested mitigations, and apply the necessary updates.

    On August 18, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-33824 and CVE-2026-55040 to their Known Exploited Vulnerabilities (KEV) Database.

    Open-source reporting indicates that CVE-2026-63520 related to Microsoft SharePoint Server is being exploited in the wild.

    Open-source reporting indicates that CVE-2026-65660 related to Microsoft SharePoint Server is being exploited in the wild.

    This is an extract. The publication continues at the source.

    Read the original at the source: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804

    Officially imported this from Canadian Centre for Cyber Security’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    This publication has changed since it was first published

    3 versions recorded. The original is kept in full — nothing is overwritten.

    1. v3 imported change on current
    2. v2 imported change on Titled: “Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 3”
    3. v1 as first published on Titled: “Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 3”

    Provenance

    Organization
    Canadian Centre for Cyber Security — imported from official source
    Official source
    https://www.cyber.gc.ca/api/cccs/rss/v1/get?feed=alerts_advisories&lang=en ATOM
    Imported
    September 24, 2026 15:00
    Versions
    3 recorded
    Identity
    https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthl...

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.