# The New Normal Gets a Number: 400 CVEs Now Counts as a Light Month.

_August 2026 Patch Tuesday arrived today with roughly 400 CVEs, making it the second-largest release in Microsoft history and still a thirty percent decline from July. One zero-day is under active exploitation, a Windows WinSock driver flaw that researchers note fits historical nation-state tradecraft, and two more were publicly disclosed before patches shipped._

_This is the fifth edition of the Brinqa Research Team monthly vulnerability landscape analysis. For new readers, the background: on April 7, Anthropic announced Project Glasswing and Claude Mythos Preview, a model capable of autonomously finding and chaining zero-day vulnerabilities at a scale and speed that previously required elite human researchers. Access was restricted to a coalition of vetted defenders, roughly 50 organizations at launch, expanded to more than 200 across 15 countries by July, including critical infrastructure operators._

## **The Numbers: The Second-Largest Release in History Feels Like a Slow Month**

_Each month we pull vendor advisory data and cross-reference it against independent analysis from Tenable, Qualys, Rapid7, CrowdStrike, BleepingComputer, SANS, and the Zero Day Initiative._

_By product family, Windows absorbed 236 CVEs, Office roughly 196 across current and 2016 servicing streams, SharePoint 30, developer tools 26, Azure 17, and Exchange Server 7._

### **One Exploited Zero-Day, Two Public Disclosures, and a Nation-State Signature**  
- **CVE-2026-68820:** Windows Ancillary Function Driver for WinSock (afd.sys) elevation of privilege, CVSS 7.0, rated only Important, and under active exploitation.  
- **CVE-2026-62832:** Publicly disclosed before patches shipped, with Microsoft assessing exploitation as likely to follow.  
- **CVE-2026-72971:** A link-following tampering flaw in the Windows Container Isolation file system filter driver (unionfs.sys), CVSS 5.5, publicly disclosed, affecting Windows 11 version 26H1.

## **The SharePoint Chain Closes, Exactly as Forecast**
_CVE-2026-63520, CVSS 8.1, is an unsafe .NET type instantiation flaw in SharePoint’s Business Connectivity Services, disclosed jointly by Microsoft and Rapid7._

## **Notable Vulnerabilities Beyond the Headliners**  
- **CVE-2026-62893, Windows Deployment Services TFTP Server RCE.**  
- **CVE-2026-62878 and CVE-2026-62815, DNS Server and Microsoft QUIC RCEs.**  
- **CVE-2026-62911, Exchange Server elevation of privilege.**  
- **The AI tooling cluster, month four.**  
- **CVE-2026-6726 and CVE-2026-6727, TPM 2.0 reference implementation.**

## **What the Security Industry Is Saying**  
**Zero Day Initiative, Dustin Childs (August 11, 2026):**  
**Tenable, Satnam Narang, Senior Staff Research Engineer (August 11, 2026):**  
**Rapid7, Stephen Fewer and team (August 11, 2026):**  
**Action1 (August 2026):**  
**Ivanti, Todd Schell (August 7, 2026 forecast):**

## **Five Recommendations Before the September Window**  
**1\. Patch the WinSock zero-day and both SharePoint fixes first, in the same emergency change.**  
**2\. Treat publicly disclosed flaws as if attacks have already started.**  
**3\. Move your deployment and management systems up the priority list.**  
**4\. Plan capacity around the real pattern: many findings, few fires.**  
**5\. Keep room in September for the disclosure wave that is now twice overdue.**

If you’re working through what AI-driven CVE volume means for your program, speak with a Brinqa Expert about where it stands today.
