Microsoft Patch Tuesday 2026 Fixes 421 Flaws, Including Three Zero‑Days Exploited by Lazarus Group
What Happened — Microsoft released its August 2026 Patch Tuesday bundle, addressing 421 vulnerabilities (62 rated Critical). Among them are three zero‑day flaws, one of which has already been weaponized by the Lazarus group to obtain SYSTEM privileges on Windows hosts.
Why It Matters for Compliance & Audit Readiness
- Unpatched critical CVEs constitute a direct control gap against SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management); continuous evidence of patch deployment is essential for audit readiness.
- Exploited zero‑days highlight the need for real‑time vulnerability monitoring and mapping to compliance controls, a core capability of Verisq’s Control Mapping service.
Who Is Affected — Enterprises across all sectors that run Windows 10/11, Windows Server, or use Microsoft Office/SharePoint, especially organizations with on‑premises Windows Deployment Services (WDS) or large document‑sharing workflows.
Recommended Actions
- Immediately apply the August 2026 updates via Windows Update or WSUS, prioritizing CVE‑2026‑62893 (TFTP RCE) and CVE‑2026‑62832 (LegacyHive EoP).
- Map each patched CVE to the relevant SOC 2 control, capture patch‑install logs as immutable audit evidence, and integrate the data into your continuous‑compliance dashboard.
Technical Notes
- Attack vector: vulnerability exploit (privilege escalation, unauthenticated RCE).
- Notable CVEs: CVE‑2026‑62893 (CVSS 9.8, unauthenticated RCE in TFTP), CVE‑2026‑62832 (EoP in User Profile Service), plus 48 Office RCE fixes.
- Exploited by Lazarus: a known APT group leveraging the privilege‑escalation flaw to gain SYSTEM rights.