Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Microsoft Patch Tuesday 2026 Fixes 421 Flaws, Including Three Zero‑Days Exploited by Lazarus Group

Microsoft’s August 2026 Patch Tuesday addressed 421 vulnerabilities, with three zero‑day flaws and one actively weaponized by the Lazarus APT group. For SOC 2‑compliant organizations, unpatched critical CVEs represent a control gap that must be documented and remediated to maintain audit readiness.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 malwarebytes.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
malwarebytes.com

Microsoft Patch Tuesday 2026 Fixes 421 Flaws, Including Three Zero‑Days Exploited by Lazarus Group

What Happened — Microsoft released its August 2026 Patch Tuesday bundle, addressing 421 vulnerabilities (62 rated Critical). Among them are three zero‑day flaws, one of which has already been weaponized by the Lazarus group to obtain SYSTEM privileges on Windows hosts.

Why It Matters for Compliance & Audit Readiness

  • Unpatched critical CVEs constitute a direct control gap against SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); continuous evidence of patch deployment is essential for audit readiness.
  • Exploited zero‑days highlight the need for real‑time vulnerability monitoring and mapping to compliance controls, a core capability of Verisq’s Control Mapping service.

Who Is Affected — Enterprises across all sectors that run Windows 10/11, Windows Server, or use Microsoft Office/SharePoint, especially organizations with on‑premises Windows Deployment Services (WDS) or large document‑sharing workflows.

Recommended Actions

  • Immediately apply the August 2026 updates via Windows Update or WSUS, prioritizing CVE‑2026‑62893 (TFTP RCE) and CVE‑2026‑62832 (LegacyHive EoP).
  • Map each patched CVE to the relevant SOC 2 control, capture patch‑install logs as immutable audit evidence, and integrate the data into your continuous‑compliance dashboard.

Technical Notes

  • Attack vector: vulnerability exploit (privilege escalation, unauthenticated RCE).
  • Notable CVEs: CVE‑2026‑62893 (CVSS 9.8, unauthenticated RCE in TFTP), CVE‑2026‑62832 (EoP in User Profile Service), plus 48 Office RCE fixes.
  • Exploited by Lazarus: a known APT group leveraging the privilege‑escalation flaw to gain SYSTEM rights.

Source: Malwarebytes Labs – Patch Tuesday August 2026

📰 Original Source
https://www.malwarebytes.com/blog/bugs/2026/08/patch-tuesday-update-now-to-fix-421-flaws-including-three-zero-days ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →