Microsoft security update graphic showing the Microsoft logo beside three colored tiles: a white tile labeled “7 Bulletins,” a red tile labeled “6 Critical,” and a purple tile labeled “1 Important.”

Regardless of what everyone thinks about AI, it’s clear that patch acceleration based on identified vulnerabilities is forcing the patch management industry to deal with the Patch Apocalypse. The magic question is how do you deal with it when even Microsoft is recommending a three-day turnaround on patching to stay ahead of the ‘AI-accelerated’ threats? The challenge is that large enterprises are constrained by testing, change control and compatibility requirements. That challenge needs to be addressed by building a process to deploy patches that matter to mitigate risk in days and stay disciplined for everything else.

The first step in this new process is to understand that not all CVEs are created equal. The patches need to be triaged to identify those CVEs that require immediate attention including those tied to known exploitation or disclosure, known malware, CISA’s KEV list, or internet-facing or unauthenticated vulnerabilities, etc. Once these CVEs are identified you can build a list of the patches to consider immediately for your environment. But you need to remain disciplined and remember even CVEs with high CVSS scores which are not exploited or are not internet facing can be handled in a second round of patching. Everything else can be addressed in a normal patch management sequence for your organization which may occur in two to three weeks. This breakdown is roughly how Ivanti Neurons handles patching with the Zero-day patch cycle meeting that three-day Microsoft standard; the Priority patch cycle happening every two weeks, and finally regular maintenance occurring roughly every three weeks or once a month.

Triaging the patches is not the only step in this new process. You need to know your environment and understand your exposure to the triaged CVEs. Based on your network knowledge, you should prioritize internet-facing and remotely exploitable systems first. Systems deeper in your environment may be able to be patched in a broader second wave. Don’t forget to consider the operational impact and disruption risk associated with key business systems; some systems may be more sensitive to patching. Armed with this knowledge you should be able to prioritize and organize systems into priority groups for patching. You can now assign patches and systems to the three patch cycles mentioned earlier. But wait!

The final step in this process is to develop a methodology to test (as needed) before deployment. History has shown that patch quality and impact of patch installation varies wildly on many factors. As an organization only you can decide how much testing is required. Questions to consider include 1) how much test time is available before our next maintenance window opens; 2) can we maintain a minimal smoke-test suite for critical systems so we are not running blindly on live systems 3) can we identify systems which are less sensitive to patches and build a fast-track smoke-test for quick turnaround; 4) and many more. The test methodology needs to match up against the proposed patch cycles to make the final decisions on how fast to run. For example, can we test the latest OS patches containing zero-day CVEs for running on critical business servers and have them deployed in three days? Ideally yes we want to, but in reality, there are security versus operational risks which may dictate another patch cycle.

In summary, only a small fraction of disclosed vulnerabilities are ever confirmed as exploited in the wild. The goal here is to test and deploy the patches addressing the highest risk systems first and methodically working through your entire corporate environment. The process needs to move quickly because another round of software updates is just around the corner in the Patch Apocalypse.

Microsoft’s exploited vulnerabilities

There is one reported exploited vulnerability this month. CVE-2026-68820 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock, rated Important. Microsoft confirms this is being exploited in the wild. This driver has been a recurring target for local privilege-escalation bugs throughout 2026, and past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges.

Microsoft’s publicly disclosed vulnerabilities

There are two publicly disclosed vulnerabilities of interest this month. CVE-2026-62832 is an elevation of privilege vulnerability in the Windows User Profile Service, rated Important. This is the flaw behind "LegacyHive," the unpatched proof-of-concept released by researcher Nightmare-Eclipse just hours after July's Patch Tuesday. This vulnerability lets a standard user coerce the User Profile Service into loading another user's registry hive — including an administrator's — to gain unauthorized access to that user's Classes registry data.

CVE-2026-72971 is a tampering vulnerability in the Windows Container Isolation FS Filter Driver (unionfs.sys), rated Important. Public disclosure ahead of a patch means exploit code could follow quickly; organizations running Windows containers, build agents or CI infrastructure on affected hosts should prioritize this update appropriately.

Ivanti security advisories

Ivanti has released two security updates for August. The updates affect Ivanti Endpoint Manager and Ivanti Neurons for Mobile Device Management. They resolve a total of three CVEs. More details and information about mitigations can be found in the August Security Advisory.

August update to-do list

  • Revisit your Apple devices to confirm the latest patches from August 6th have been deployed. Likewise, double-check Oracle Java and other Oracle apps were updated from the monthly CPU release. Also, remember Oracle is releasing security updates monthly now.
  • The priority this month is to patch the Windows operating systems. The Winsock vulnerability CVE-2026-68820 is being exploited in the wild and impacts all operating systems from Windows Server 2012 to the latest versions of Windows 11 and Server 2025 — patch immediately. These updates will also address CVE-2026-62832 which has been disclosed with no official patch for more than a month. It's fixed as of today's release, so treat these OS updates as a priority.