Patch Tuesday Dashboard

Assurance Security Dashboard: August 2026 Patch Tuesday

August 2026 Assurance Security Dashboard infographic: 403 CVEs across Windows, Browser, Developer Tools, Office, Exchange and SQL Server with 48 Critical and 3 zero-day flag(s)

Microsoft’s August 2026 Patch Tuesday addresses 403 CVEs across the August security release. The infographic above summarises severity and risk level by product family; the prose below unpacks the items that need attention this cycle. 3 CVEs carry a zero-day flag (publicly disclosed and/or being exploited in the wild).

August 2026 Patch Tuesday: updates by product family

  • Windows - 18 Critical, 214 Important, 1 Moderate, top CVSS 9.8. Action: Patch Now.
  • Browsers - no updates this month.
  • Development - 27 Important, top CVSS 8.8. Action: Schedule.
  • Office - 29 Critical, 99 Important, top CVSS 10. Action: Patch Now.
  • Exchange - 1 Critical, 6 Important, top CVSS 8.8. Action: Patch Now.
  • SQL Server - 1 Important, top CVSS 8.8. Action: Schedule.

Notable CVEs this cycle

  • CVE-2026-68820 (Windows) - Exploited, CVSS 7.
  • CVE-2026-72971 (Windows) - Publicly Disclosed, CVSS 5.5.
  • CVE-2026-62832 (Windows) - Publicly Disclosed, CVSS 7.8.

Patch now: Windows, Office, Exchange. Critical-rated or actively exploited vulnerabilities drive these into the immediate-action queue.

Schedule: Development, SQL Server. Important-rated vulnerabilities to roll into the regular monthly update cycle.

Every patch, every platform change, every application update is a risk-based decision under uncertainty. Readiness Assurance turns that uncertainty into prescriptive guidance - where applications are scanned, tested, documented, and delivered with certainty into production.