- 42Critical
- 355Important
- 1Moderate
- 0Low
Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.
Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.

This month’s update includes patches for:
- .NET
- .NET Core
- .NET Framework
- AMD Zen
- Active Directory Certificate Services (AD CS)
- Application Information Services
- Azure Active Directory
- Azure CycleCloud
- Azure Monitor Agent
- Azure Storage Explorer
- Capability Access Management Service (camsvc)
- Desktop Window Manager
- Dynamics Business Central
- GitHub Copilot and Visual Studio Code
- Microsoft Azure Attestation service and Device Health Attestation Service
- Microsoft COM for Windows
- Microsoft Defender for Endpoint
- Microsoft Digest Authentication
- Microsoft Dynamics 365 (on-premises)
- Microsoft Entra Connect Sync
- Microsoft Exchange Server
- Microsoft High Performance Computing (HPC) Pack
- Microsoft Identity Services
- Microsoft Local Security Authority Server (lsasrv)
- Microsoft Office
- Microsoft Office Access
- Microsoft Office Excel
- Microsoft Office Graphics Component
- Microsoft Office Outlook
- Microsoft Office PowerPoint
- Microsoft Office SharePoint
- Microsoft Office Word
- Microsoft OneDrive
- Microsoft PowerShell
- Microsoft PowerShell Core
- Microsoft QUIC
- Microsoft Remote Registry Service
- Microsoft Teams Mobile
- Microsoft Teams for Android
- Microsoft Windows Codecs Library
- Microsoft Windows Media Foundation
Source: Tenable Blog