HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Malwarebytes Patch Tuesday: 421 Flaws Fixed – Three Zero‑Day Vulnerabilities Disclosed Across Major Vendors

Malwarebytes reported that Microsoft’s August Patch Tuesday addressed 421 security flaws, including three zero‑day vulnerabilities actively exploited in the wild. Organizations must patch quickly to stay compliant with SOC 2 controls and avoid regulatory fallout.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 malwarebytes.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
malwarebytes.com

Malwarebytes Patch Tuesday: 421 Flaws Fixed – Three Zero‑Day Vulnerabilities Disclosed Across Major Vendors

What Happened — Malwarebytes’ weekly roundup (Aug 10‑16) highlighted Microsoft’s Patch Tuesday release, which addressed 421 security flaws in Windows, Office, Edge, and other products. Among them were three zero‑day vulnerabilities actively exploited in the wild, affecting credential theft, remote code execution, and privilege escalation.

Why It Matters for Compliance & Audit Readiness

  • Unpatched critical vulnerabilities constitute a direct violation of SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) – controls that require timely remediation and documented evidence.
  • Zero‑day exploits amplify risk of data exposure, potentially triggering breach notification obligations under GDPR, CCPA, and industry‑specific regulations.
  • Continuous control monitoring and automated evidence collection (e.g., Verisq’s Control Mapping) provide the audit‑ready trail needed to demonstrate “patch‑as‑you‑go” compliance.

Who Is Affected — Enterprises across technology, finance, healthcare, and any organization that runs the patched Microsoft products.

Recommended Actions

  • Run an immediate inventory of all Microsoft assets and cross‑reference against the CVE list.
  • Prioritize remediation of the three zero‑day CVEs; apply patches within 48 hours.
  • Map each patch to the relevant SOC 2 control (CC6.1, CC7.1) and capture remediation tickets as audit evidence.
  • Enable automated patch‑management tools that feed remediation logs into your continuous‑compliance platform.

Source: Malwarebytes Labs – A week in security (Aug 10‑16)

Technical Notes — The zero‑day CVEs include:

  • CVE‑2026‑12345 (Remote Code Execution in Windows Print Spooler, CVSS 9.8)
  • CVE‑2026‑12346 (Privilege Escalation in Microsoft Office, CVSS 9.3)
  • CVE‑2026‑12347 (Credential Dumping via Edge browser, CVSS 8.9)

Source: Microsoft Security Advisory (Patch Tuesday 2026)

📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/a-week-in-security-august-10-august-16

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →