Microsoft released August 2026 patches and more - Aug 16, 2026

Featured

Microsoft released August 2026 patches

The updates fix 400 security vulnerabilities in total, including 3 zero-day vulnerabilities.

This Week’s Updates

Breaches

Valve is notifying European Steam hardware customers that their data was stolen in a hack of shipping partner CEVA Logistics

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after unusual activity on third-party vendor servers

Supply chain giant Wesco confirmed it is investigating a cybersecurity incident after ExfilSquad claimed data theft

Trezor disclosed a breach affecting nearly 14,000 customers after its logistics partner ShipMonk was hacked

ShinyHunters stole personal information from 1.6 million RingCentral accounts in a July intrusion

Shell confirmed it is investigating a potential security incident after Clop claimed to have stolen 89GB of data

Vulnerabilities

CISA warned that a critical command injection flaw in Progress Kemp LoadMaster is being actively exploited

Ransomware gangs are exploiting two recently patched SonicWall SMA1000 flaws, including a maximum-severity SSRF bug

Cisco warned of two high-severity Secure Endpoint Connector flaws that crash the ClamAV scanning process in DoS attacks

CISA confirmed ransomware gangs are abusing a high-severity Microsoft SharePoint RCE flaw exploited since early July

Cisco warned that a high-severity Secure Firewall ASA and FTD VPN flaw is being exploited to remotely crash devices

Attackers are already using Rapid7's published proof-of-concept exploit for a critical Microsoft SharePoint vulnerability

Hackers exploited Windows zero-day CVE-2026-68820 against defense-sector firms in Operation Dream Job

Attackers are exploiting critical Adobe Commerce and Magento flaw CVE-2026-71362 to hijack customer accounts

Patched VMware vCenter Syslog Server flaw CVE-2026-59310 is being exploited to deploy a reverse SSH tool for persistence

Microsoft released patches for the "LegacyHive" Windows zero-day disclosed after July 2026 Patch Tuesday

A maximum-severity SAP Commerce Cloud RCE flaw patched three days earlier is already being targeted in attacks

Next
Next

Microsoft Released August 2026 Software Updates