Microsoft patches 400 flaws including 3 zero-days: update Windows NOW
Image: BleepingComputerMicrosoft released its August 2026 security update, fixing about 400 vulnerabilities, including a wormable remote code execution flaw and three zero-days already under active exploitation. If you run Windows, update today.
The most serious items in the bundle
The patches include critical vulnerabilities in components such as Windows AFD.sys and DNS, a combination that can let an attacker spread from machine to machine with no user interaction — the classic “worm” scenario — and take over entire corporate networks.
Zero-days under active attack
Three of the fixed flaws were already being used by attackers in the wild before the patch existed. These are the most dangerous vulnerabilities: by the time Microsoft announces them, criminals are already a step ahead, and the race is to apply the fix before the rest of the malware catches up.
Why it matters
Companies that delay updates become the easiest targets. Experts’ recommendation is blunt: install the patch within days, prioritizing servers and internet-exposed machines, and verify that backup systems are up to date.
The key figure
400 flaws. The size of the August bundle. And 3 zero-days: those already being exploited when Microsoft released the patch.


