- Microsoft addressed 421 CVEs across its products in the August 2026 security release.
- 236 CVEs are reported as affecting Windows 11, while the remaining vulnerabilities affect products such as Office, SharePoint, Azure, Exchange, and others.
- CVE-2026-68820 is a Windows zero-day affecting the Ancillary Function Driver for WinSock (afd.sys).
- Microsoft says the zero-day is already being exploited in the wild and could allow an authenticated attacker to gain SYSTEM privileges.
Microsoft’s August 2026 Patch Tuesday (KB5121003) release addresses 421 CVEs across its products, including 236 affecting Windows 11. The release also patches a Windows zero-day that Microsoft says is being exploited in the wild, making the latest security update one users should not deliberately postpone.
However, an important detail is getting lost in much of the coverage. The 421 figure is the total CVE count across Microsoft’s products, not the number of vulnerabilities affecting Windows 11.
That distinction matters because saying Microsoft “fixed 421 bugs on Windows 11” gives readers the wrong impression about what actually shipped to their computers.
Microsoft addressed 421 CVEs across its products
Microsoft’s Security Update Guide lists the vulnerabilities addressed in the August release. Security researchers tracking the release put the total at 421 CVEs, including 236 affecting Windows 11.
The remaining CVEs span Microsoft’s broader product portfolio. For instance, 98 vulnerabilities affect Office, 30 affect SharePoint Server, 26 affect Developer Tools, 17 affect Azure, 7 affect Exchange Server, 1 affects Defender, and 6 affect other products.
That’s why the headline “Microsoft fixed 421 bugs in Windows 11” isn’t accurate.
Windows 11 receives a cumulative security update that includes fixes for vulnerabilities applicable to the operating system. Microsoft is not sending 421 separate fixes to every computer.
One Windows zero-day deserves immediate attention
The most important vulnerability in the August release isn’t the number 236. It’s CVE-2026-68820.
The vulnerability affects the “Windows Ancillary Function Driver for WinSock” (afd.sys). Microsoft says an authenticated attacker could exploit the flaw to gain SYSTEM privileges, and the vulnerability is already being exploited in the wild.
That’s a local privilege-escalation vulnerability. An attacker generally needs some level of access to the machine first, so this isn’t the same as saying someone can simply attack any computer remotely and immediately take control.
However, once an attacker has established a foothold, obtaining SYSTEM-level privileges can give them substantially greater control over the machine.
Microsoft still wants organizations to patch quickly
The larger issue for users is not whether August contains 421 CVEs. It’s whether the security vulnerabilities affecting their particular system have been patched.
Microsoft has been warning that AI is changing how quickly vulnerabilities can be discovered and potentially exploited. The company has also been using AI-assisted security systems to find vulnerabilities in its own software faster.
That creates a race between defenders and attackers. Finding more vulnerabilities isn’t necessarily evidence that software suddenly became worse. It can also mean that Microsoft is getting better at discovering problems that previously might have remained hidden.
However, once the company publishes a security update, attackers can study the vulnerability and the remediation. That’s one reason delaying security updates for weeks is increasingly difficult to justify.
Pureinfotech’s Take
I think the 421 number is getting more attention than it deserves. It’s the total CVE count across Microsoft’s products, not 421 Windows 11 bugs. The exploited Windows zero-day is a much better reason to install this month’s update.
How quickly do you install Windows 11 security updates?
Voting closes: August 21, 2026 1:00 pm
I don’t usually recommend rushing to install every update, but I wouldn’t deliberately delay this one. If a vulnerability is already being exploited, there’s little benefit in waiting weeks to install the fix.

