Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
CVE-2026-68820 and the lone known active exploit
Among the 398 fixes, Microsoft addressed a single known “zero day”: CVE-2026-68820, a privilege-escalation flaw in the Windows driver afd.sys. Automox characterized afd.sys as “the driver behind Windows socket connections on effectively every endpoint,” and Automox’s Landon Miles described CVE-2026-68820 as “step two in a chain: an attacker phishes their way into a low-privilege foothold, then uses the driver flaw to take the box.” Miles added, “The 7.0 score reflects the high attack complexity, because race conditions are fiddly. The exploit has to be thrown over and over until the timing lands. Someone is clearly landing it anyway.”
Microsoft also flagged CVE-2026-62832, another privilege escalation in the Windows User Profile Service that the company labeled likely to be exploited; that bug may be related to the recent “LegacyHive” public disclosure from the prolific bug hunter known as Nightmare Eclipse. A third publicly disclosed issue, CVE-2026-72971, is a low‑impact local tampering vulnerability that Microsoft says is unlikely to be exploited. Redmond rated 42 of the 398 flaws as “critical,” meaning they could allow remote code execution with minimal user interaction.
Patch volume, AI, and the new cadence
This month’s 398 patches follow a record-breaking 570+ updates last month and roughly double June’s near-200 fixes. Microsoft has attributed the recent surge to vulnerability discoveries aided by artificial intelligence, and other major vendors are likewise shipping more frequent, abundant updates: Adobe has moved to twice-monthly security bulletins, and Cisco, Google, Mozilla and Oracle “are shipping updates far more frequently and abundantly,” the reporting notes.
That increased discovery rate, the company and outside experts say, is driven in significant part by AI tools that can surface bugs at scale. But discovery has outpaced reliable automated repair: the same AI systems finding vulnerabilities are now being used to suggest fixes, and that creates a new set of risks and operational questions.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAI-generated patches: promise and pitfalls
Researchers at 1Password tested large language models (LLMs) that generated patches for complex, newly disclosed flaws and found the suggested fixes “failed to fix the flaw or added a new weakness in the process (or both) more than half the time.” Ed Skoudis, president of the SANS Technology Institute, wrote that his team has seen excellent results using AI to generate patches but only when “there are humans in the loop to test the suggested fixes and push for iterative improvements.” Skoudis warned: “Don’t expect one-shot AI patching to work reliably. Instead, iterate, test, challenge, improve, and verify. AI can be an extraordinary patching partner, but today it still needs a skilled human at the keyboard.”
What this means for security teams, chief security officers, and end users
- Security teams and technologists: Expect higher monthly patch loads and build processes that include testing AI-suggested fixes. Tyler Reguly of Fortra urged leaders to check how teams are handling increased workloads and to support workflow changes required for safe rollouts.
- Chief security officers and procurement leaders: Reguly counseled caution on speed: “There’s no need to rush these updates, no matter what various vendors and organizations try to tell you. You need to make sure that you are rolling out safe updates that will not negatively impact your systems.” He added: “If you’re a chief security officer talk to your teams about how they are shifting or modifying their workflows to better accommodate the patching shift that we’re seeing and support them across various organizational units by enabling the changes they want to see made.”
- End users and system owners: Back up systems and data before applying this month’s large bundle. The day after Patch Tuesday is sometimes called Reboot Wednesday; the reporting recommends waiting a few days in case a problematic patch needs to be corrected by Microsoft.
Operational guidance and where to find per-patch detail
Only one of the nearly 400 vulnerabilities patched this month is known to be actively exploited, which should factor into prioritization and testing. Organizations that run production environments will still need to balance speed and safety: test fixes before broad deployment, coordinate across organizational units, and consider staged rollouts. For a per-patch breakdown by severity and urgency, the SANS Internet Storm Center provides a clickable roundup that security teams can use to triage and plan deployments.
Microsoft’s August bundle illustrates a widening asymmetry: AI is accelerating the discovery of vulnerabilities, and vendors and defenders are scrambling to adapt patching practices and human workflows. As the story itself notes, “the jury is still out on whether AI technologies will turn out to be as good at fixing vulnerabilities as they are at finding and exploiting them.” That unresolved balance — faster discovery, imperfect automated fixes, and heavier monthly workloads for human teams — is the immediate operational challenge for enterprises and the security community.
Source: KrebsOnSecurity — Microsoft Plugs Nearly 400 Security Holes




