August 2026 Patch Tuesday: 400 CVEs, One Real Fire | Brinqa

The New Normal Gets a Number: 400 CVEs Now Counts as a Light Month.

August 2026 Patch Tuesday arrived today with roughly 400 CVEs, making it the second-largest release in Microsoft history and still a thirty percent decline from July. One zero-day is under active exploitation, a Windows WinSock driver flaw that researchers note fits historical nation-state tradecraft, and two more were publicly disclosed before patches shipped.

This is the fifth edition of the Brinqa Research Team monthly vulnerability landscape analysis. For new readers, the background: on April 7, Anthropic announced Project Glasswing and Claude Mythos Preview, a model capable of autonomously finding and chaining zero-day vulnerabilities at a scale and speed that previously required elite human researchers. Access was restricted to a coalition of vetted defenders, roughly 50 organizations at launch, expanded to more than 200 across 15 countries by July, including critical infrastructure operators.

The Numbers: The Second-Largest Release in History Feels Like a Slow Month

Each month we pull vendor advisory data and cross-reference it against independent analysis from Tenable, Qualys, Rapid7, CrowdStrike, BleepingComputer, SANS, and the Zero Day Initiative.

By product family, Windows absorbed 236 CVEs, Office roughly 196 across current and 2016 servicing streams, SharePoint 30, developer tools 26, Azure 17, and Exchange Server 7.

One Exploited Zero-Day, Two Public Disclosures, and a Nation-State Signature

The SharePoint Chain Closes, Exactly as Forecast

CVE-2026-63520, CVSS 8.1, is an unsafe .NET type instantiation flaw in SharePoint’s Business Connectivity Services, disclosed jointly by Microsoft and Rapid7.

Notable Vulnerabilities Beyond the Headliners

What the Security Industry Is Saying

Zero Day Initiative, Dustin Childs (August 11, 2026):
Tenable, Satnam Narang, Senior Staff Research Engineer (August 11, 2026):
Rapid7, Stephen Fewer and team (August 11, 2026):
Action1 (August 2026):
Ivanti, Todd Schell (August 7, 2026 forecast):

Five Recommendations Before the September Window

1. Patch the WinSock zero-day and both SharePoint fixes first, in the same emergency change.
2. Treat publicly disclosed flaws as if attacks have already started.
3. Move your deployment and management systems up the priority list.
4. Plan capacity around the real pattern: many findings, few fires.
5. Keep room in September for the disclosure wave that is now twice overdue.

If you’re working through what AI-driven CVE volume means for your program, speak with a Brinqa Expert about where it stands today.