Virtual Administrator’s August 2026 Patch Recommendations

Patch Recommendations

Virtual Administrator’s August Patch Recommendations

 

This month Microsoft released patches for 398 vulnerabilities with 62 rated "Critical" in severity.

All new patches will be approved in our patch policy.

We have about 400 vulnerabilities patched this month which is likely the new normal. On the bright side we only have one (CVE-2026-68820) actively being exploited, and two (CVE-2026-62832,CVE-2026-72971) publicly disclosed as zero-days.

  • CVE-2026-68820 is an Elevation of Privilege vulnerability affecting Windows Ancillary Function Driver for WinSock.
  • CVE-2026-62832 is another Elevation of Privilege vulnerability affecting Windows User Profile Service.
  • CVE-2026-72971 is an improper link resolution issue in the Windows Container Isolation file system filter driver (unionfs.sys) allowing an authorized attacker to perform tampering locally.

Last month's issue with some Dell machine was addressed with an out-of-band – see "FYI" below. New standalone SSUs for Windows 10 1607/Server 2016.

 

Disclosed: CVE-2026-62832, CVE-2026-72971

Exploited: CVE-2026-68820

 

Security Update Guide

https://msrc.microsoft.com/update-guide/en-us

 

Microsoft Security Advisories

ADV990001 | Latest Servicing Stack Updates (Published:3/1/2018 | Last Updated: 8/11/2026)

https://msrc.microsoft.com/update-guide/en-us/vulnerability/ADV990001

Reason for Revision: A Servicing Stack Update has been released for some versions of Windows.

NOTE: The Windows 10 Security Stack Updates are included in the monthly Cumulative Updates.

 

Heads Up!

Secure Boot certificates used by most Windows devices expired starting in June 2026.

Windows Secure Boot certificate expiration and CA updates

https://support.microsoft.com/en-us/servicing/os/secure-boot/2025/06/windows-secure-boot-certificate-expiration-and-ca-updates

Secure Boot playbook for certificates expiring in 2026

https://techcommunity.microsoft.com/blog/windows-itpro-blog/secure-boot-playbook-for-certificates-expiring-in-2026/4469235

 

FYI

Microsoft released out-of-band patches on July 18th to address last month's issue on some Dell machines causing changes in performance, power consumption, or system behavior. Machines affected were blocked from receiving the July CU. Those machines will need the OOB patch but machines that already installed the July CU do not. We immediately approved the OOB patch when it was released.

July 18, 2026—KB5121767 (OS Builds 26200.8894 and 26100.8894) Out-of-band

https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/kb5121767-out-of-band

July 18, 2026—Hotpatch KB5121768 (OS Builds 26200.8893 and 26100.8893) Out-of-band

https://support.microsoft.com/en-us/servicing/os/hotpatch/windows-11/2026/kb5121768-hotpatch-out-of-band

 

Known Issues

The only new known issue reported by Microsoft is with Exchange Server where Wrapper messages appear in shared mailbox in hybrid environments after installing the June 2026 Security Update

Microsoft continues to list unresolved older problems under the Known Issues for new patches. So if you have not yet experienced one of these issues it is unlikely it will occur now.

Good resource for known issues with Windows 10/11/Server patches. Find the version and click on "Known issues".

Windows release health

https://docs.microsoft.com/en-us/windows/release-health/

 

"Wrapper messages appear in shared mailbox in hybrid environments after installing the June 2026 Security Update"

https://support.microsoft.com/en-us/servicing/exchange/server/hotfix/2026/5105719

Affected platforms: Exchange Server 2016 CU23, 2019 CU14/CU15, Subscription Edition RTM

Symptoms: Your organization uses an Exchange hybrid deployment. After you install the June 2026 Security Update (SU) for Exchange Server, messages that are Sent As, or Sent on Behalf of, the shared mailbox may also be delivered to the Inbox folder of the shared mailbox as attachments with the following wrapper message:

“The attached message was sent by a member of this shared mailbox. Usually, it would appear in Sent Items, but your service is currently being upgraded. Things will be back to normal after the upgrade.”

Workaround: To work around this issue, create a setting override by running the following command in an elevated Exchange Management Shell window. This disables the change that was introduced in the June 2026 Security Update (SU) for Exchange Server.

1. New-SettingOverride -Name "DisableBlockSharedAndUserMailboxHeaders" -Component Transport -Section BlockSharedAndUserMailboxHeaders -Parameters @("Enabled=false") -Reason "Mitigate Sent Items issue in Exchange hybrid"

2. Get-ExchangeDiagnosticInfo -Process Microsoft.Exchange.Directory.TopologyService -Component VariantConfiguration -Argument Refresh

Status: Microsoft is investigating this issue and will update this article as more information becomes available.

 

Monthly Rollup/Security Only/Windows 10,11/Server 2016,2019,2022,2025 KBs

Links are https://support.microsoft.com/en-us/help/####### with the KB number only.

 

Security and Quality Rollup

  • KB5120385 – Windows Server 2012 R2 (ESU)
  • KB5120386 – Windows Server 2012 (ESU)

 

Cumulative Updates

Windows 10

  • KB5120249 – Version 21H2 "November 2021 Update" (OS Build 19044) (ESU)
  • KB5120249 – Version 22H2 "November 2022 Update" (OS Build 19045) (ESU)

(Versions 1507,1511,1607,1703,1709,1803,1809,1903,1909,2004,20H2,21H1 are no longer under support)

 

Windows 11

  • KB5120240 – 23H2 (OS Build 22631)
  • KB5121003 – 24H2 (OS Build 26100)
  • KB5121003 – 25H2 (OS Build 26200)
  • KB5121000 – 26H1 (OS Build 28000)

(Version 21H2,22H2 are no longer under support)

 

Windows Server

  • KB5120418 – Server 2016 (EOS January 2027)
  • KB5120238 – Server 2019 (EOS January 2029)
  • KB5120242 – Server 2022 (OS Build 20348)
  • KB5120233 – Server 2025 (OS Build 26100)

 

August 2026 updates for Microsoft Office

https://support.microsoft.com/en-us/servicing/office/hotfix/august/5123577

 

Notable CVEs

 

CVE-2026-62823 | Windows DHCP Server Remote Code Execution Vulnerability (Cumulative Update/Monthly Rollup)

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62823

Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network.

 

CVE-2026-62832 | Windows User Profile Service Elevation of Privilege Vulnerability (Cumulative Update)

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62832

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally. An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user's registry hive. Successful exploitation could allow the attacker to access or modify another user's data and gain administrator privileges. User interaction is not required.

 

CVE-2026-62893 | Windows Deployment Services TFTP Server Remote Code Execution Vulnerability (Cumulative Update)

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62893

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.

 

CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (Cumulative Update/Monthly Rollup)

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-68820

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required.

 

CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability (Cumulative Update)

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-72971

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.