Cisco Talos reports that Microsoft marked 62 August vulnerabilities critical and noted that one was exploited in the wild.
What to know
- Cisco Talos reports that Microsoft’s August 2026 security update includes 421 vulnerabilities across a range of products.
- Microsoft marked 62 of the vulnerabilities as critical, including 40 remote code execution vulnerabilities.
- Microsoft noted that one vulnerability disclosed this month was exploited in the wild, but the Talos source does not identify it.
- Microsoft considers CVE-2026-62893, CVE-2026-65665 and CVE-2026-62823 more likely to be exploited.
- Talos released Snort rules covering attempts to exploit some of the disclosed vulnerabilities and says additional rules may be released later.
What Microsoft’s August update includes
According to Cisco Talos, Microsoft released its monthly security update on August 11, 2026. The update includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as critical.
Talos reports that Microsoft noted one of the vulnerabilities disclosed this month was exploited in the wild. The source does not identify which vulnerability this refers to.
Of the 62 vulnerabilities Microsoft marked critical, 40 are remote code execution vulnerabilities. The effect of a remote code execution flaw depends on the affected product and vulnerability.
Vulnerabilities Microsoft considers more likely to be exploited
Talos reports that Microsoft considers exploitation of several vulnerabilities more likely. The explicitly listed examples include CVE-2026-62893, a remote code execution vulnerability in Windows Deployment Services TFTP Server with a CVSS base score of 9.8; CVE-2026-65665, a remote code execution vulnerability in Microsoft SharePoint Server with a score of 8.8; and CVE-2026-62823, a remote code execution vulnerability in Windows DHCP Server with a score of 8.8.
Talos also lists numerous other vulnerabilities that Microsoft considers more likely to be exploited, including issues affecting Visual Studio Code, Windows components, Microsoft SharePoint Server and other products. The source provides the CVE identifiers and vulnerability names but does not provide further technical details for each item in that list.
Other vulnerabilities highlighted by Talos
Talos separately describes vulnerabilities affecting products including Remote Desktop Client, Windows Active Directory Certificate Services, Windows DNS Server, Windows Secure Socket Tunneling Protocol, Microsoft Office, Exchange Server and SharePoint Server. The report gives selected CVE identifiers, vulnerability types, attack conditions and CVSS base scores for these issues.
The Talos report also identifies two vulnerabilities that Microsoft considers unlikely to be exploited: CVE-2026-65789, affecting Windows DNS Server, and CVE-2026-65791, affecting Windows iSCSI Target Service. These classifications reflect Microsoft’s assessment as reported by Talos and should not be treated as a guarantee that exploitation cannot occur.
Snort coverage
Cisco Talos says it is releasing a new Snort ruleset that detects attempts to exploit some of the vulnerabilities disclosed in Microsoft’s August update. Talos notes that additional rules may be released later and that existing rules may change as more information becomes available.
The reported Snort 2 rule coverage is 1:66902-1:66910, 1:66912-1:66923, 1:66929-1:66932 and 1:66935-1:66948. Snort 3 coverage is 1:66902 and 1:301589-1:301607.
Talos says Cisco Secure Firewall customers should use the latest ruleset update by updating their SRU. It says open-source Snort Subscriber Ruleset customers can obtain the latest rule pack available for purchase on Snort.org.
What readers should check
As general guidance, users and organizations can first identify which Microsoft products and services they operate, then review the applicable information in Microsoft’s security update materials. Talos says Microsoft’s update page contains the complete list of vulnerabilities disclosed this month.
The Talos report names products and services including Windows, Office, SharePoint Server, Exchange Server, Windows DHCP Server, Windows DNS Server and Remote Desktop Client. Applicability depends on the specific product and installation, so the vulnerability count alone does not establish whether a particular device or environment is affected.
Does this affect me?
- Who may be affected
- Windows users, Technicians
- How to check
- Confirm whether you use the named product, service, version, or account described by the primary source.
- What to do
- Follow the vendor or agency guidance that applies to your environment; prioritize confirmed updates and account protections.
- What to avoid
- Do not install unsolicited fixes, call numbers from pop-ups, or assume every device is affected.
Common questions
Does this affect every computer or account?
No. Exposure depends on the affected product, version, configuration, or service described by the primary source.
What is the safest first step?
Verify the product or account involved and use the official source or vendor update path rather than links from unsolicited messages.
Primary source
Source: Cisco Talos, “Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities.” https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/ Read the complete original source.
Get the important updates without the noise
Choose the devices and topics you care about in Cyber Alerts.
Article history: Published Aug 12, 2026 at 11:31 pm EDT. Updates and corrections are noted here when material facts change.
