HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Microsoft Patch Tuesday 2026 Fixes 421 Flaws, Including Three Zero‑Days Exploited by Lazarus Group

Microsoft’s August 2026 Patch Tuesday addressed 421 vulnerabilities, with three zero‑day flaws and one actively weaponized by the Lazarus APT group. For SOC 2‑compliant organizations, unpatched critical CVEs represent a control gap that must be documented and remediated to maintain audit readiness.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 malwarebytes.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
malwarebytes.com

Microsoft Patch Tuesday 2026 Fixes 421 Flaws, Including Three Zero‑Days Exploited by Lazarus Group

What Happened — Microsoft released its August 2026 Patch Tuesday bundle, addressing 421 vulnerabilities (62 rated Critical). Among them are three zero‑day flaws, one of which has already been weaponized by the Lazarus group to obtain SYSTEM privileges on Windows hosts.

Why It Matters for Compliance & Audit Readiness

  • Unpatched critical CVEs constitute a direct control gap against SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); continuous evidence of patch deployment is essential for audit readiness.
  • Exploited zero‑days highlight the need for real‑time vulnerability monitoring and mapping to compliance controls, a core capability of Verisq’s Control Mapping service.

Who Is Affected — Enterprises across all sectors that run Windows 10/11, Windows Server, or use Microsoft Office/SharePoint, especially organizations with on‑premises Windows Deployment Services (WDS) or large document‑sharing workflows.

Recommended Actions

  • Immediately apply the August 2026 updates via Windows Update or WSUS, prioritizing CVE‑2026‑62893 (TFTP RCE) and CVE‑2026‑62832 (LegacyHive EoP).
  • Map each patched CVE to the relevant SOC 2 control, capture patch‑install logs as immutable audit evidence, and integrate the data into your continuous‑compliance dashboard.

Technical Notes

  • Attack vector: vulnerability exploit (privilege escalation, unauthenticated RCE).
  • Notable CVEs: CVE‑2026‑62893 (CVSS 9.8, unauthenticated RCE in TFTP), CVE‑2026‑62832 (EoP in User Profile Service), plus 48 Office RCE fixes.
  • Exploited by Lazarus: a known APT group leveraging the privilege‑escalation flaw to gain SYSTEM rights.

Source: Malwarebytes Labs – Patch Tuesday August 2026

📰 Original Source
https://www.malwarebytes.com/blog/bugs/2026/08/patch-tuesday-update-now-to-fix-421-flaws-including-three-zero-days

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →