Zero Day Initiative | Blog
Follow
The August 2026 Security Update Review
The latest security patches from Adobe and Microsoft have been released, with Adobe addressing 51 unique CVEs in various products, including ColdFusion, Commerce, Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. The patches from Adobe are considered critical, with the highest CVSS score being 10.0, and are recommended to be deployed as soon as possible, especially for Campaign Classic and ColdFusion. Microsoft's release includes 398 new CVEs, with 62 rated as Critical, and only one listed as being under active attack. The Microsoft patches impact a wide range of products, including Windows, Office, and Azure, and include several remote code execution vulnerabilities. One notable vulnerability is the Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability, which allows attackers to execute code at SYSTEM level. Another significant vulnerability is the Windows DNS Server Remote Code Execution Vulnerability, which allows a remote, unauthenticated attacker to execute code with elevated privileges. The patches also include several elevation of privilege vulnerabilities in Microsoft Exchange Server, Azure, and other products. It is essential to test and deploy these patches quickly, especially for internet-facing systems, to prevent potential attacks. The large number of patches released this month is consistent with the trend of increasing patch volumes, and it is crucial to stay on top of these updates to ensure the security of systems and data. Overall, the latest security patches from Adobe and Microsoft highlight the importance of regular updates and patch management to prevent cyber attacks and protect sensitive information.