CRITICAL 3 min read 12 Aug 2026

Microsoft August 2026 Patch Tuesday fixes 421 CVEs, one exploited zero-day Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-68820, cve-2026-62832, cve-2026-72971, cve-2026-62878, cve-2026-62893, cve-2026-62815, cve-2026-59124, cve-2026-62911, cve-2026-6726, cve-2026-6727

Key findings
01
Still active: Microsoft August 2026 Patch Tuesday fixes 421 CVEs, one exploited zero-day
CRITICAL
First reported 2026-08-07; ongoing coverage. Microsoft's August release fixes a large Windows, Office, SharePoint, Azure, Developer Tools, Exchange, TPM, DNS, DHCP, QUIC, and Excel vulnerability set.
02
Wesco confirms security incident after ExfilSquad claims data theft
INFO
Wesco confirmed a security incident after ExfilSquad claimed data theft, leaving victim-impact and exposure details still developing from a single incident-reporting source.
03
BdThemes supply-chain attack poisons JSON to create rogue WordPress admins
INFO
A compromise of a BdThemes remote JSON/API path let attackers inject script into WordPress admin pages without changing plugin source in the official repository.
04
Still active: Framework loses customer data in Metabase zero-day attack
INFO
First reported 2026-08-11; ongoing coverage. A Metabase unauthenticated SQL injection in the reset-password endpoint can lead to administrator access, credential exposure, data export, and configuration changes.

Executive assessment

Today's brief leads with Microsoft August 2026 Patch Tuesday fixes 421 CVEs, one exploited zero-day. All 4 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Still active: Microsoft August 2026 Patch Tuesday fixes 421 CVEs, one exploited zero-day

Coverage status: First reported 2026-08-07; ongoing coverage.

What changed: Microsoft's August release fixes a large Windows, Office, SharePoint, Azure, Developer Tools, Exchange, TPM, DNS, DHCP, QUIC, and Excel vulnerability set. Multiple sources identify CVE-2026-68820 in Windows Ancillary Function Driver for WinSock as exploited in the wild, with Check Point attribution to Lazarus-linked activity in secondary reporting.

Technical evidence: CVE-2026-62878; CVSS v3.1 9.8; weakness ['CWE-121']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Map CVE-2026-62878 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-fixes-400-flaws-3-zero-days/>)

Finding 02 — Wesco confirms security incident after ExfilSquad claims data theft

What changed: Wesco confirmed a security incident after ExfilSquad claimed data theft, leaving victim-impact and exposure details still developing from a single incident-reporting source. Treat as watchlist-grade until victim statements or regulatory filings add scope, affected data classes, and remediation status.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: The cited source reports an active supply-chain compromise; exposure depends on use of the affected packages rather than exploitation of a single vulnerability.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-after-exfilsquad-claims-data-theft/>)

Finding 03 — BdThemes supply-chain attack poisons JSON to create rogue WordPress admins

What changed: A compromise of a BdThemes remote JSON/API path let attackers inject script into WordPress admin pages without changing plugin source in the official repository. Reporting says affected Elementor/WooCommerce add-ons were closed pending review and administrators should inspect users, plugin files, and suspicious admin activity.

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: The cited source reports an active supply-chain compromise; exposure depends on use of the affected packages rather than exploitation of a single vulnerability.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html>)

Finding 04 — Still active: Framework loses customer data in Metabase zero-day attack

Coverage status: First reported 2026-08-11; ongoing coverage.

What changed: A Metabase unauthenticated SQL injection in the reset-password endpoint can lead to administrator access, credential exposure, data export, and configuration changes. GitHub's Metabase advisory says active exploitation is confirmed and The Register reports Framework customer data access tied to the same issue.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.theregister.com](<https://www.theregister.com/personal-tech/2026/08/10/framework-loses-customer-data-in-metabase-zero-day-attack/5285302>)

cve-2026-59124cve-2026-62815cve-2026-62832cve-2026-62878cve-2026-62893cve-2026-62911cve-2026-6726cve-2026-6727cve-2026-68820cve-2026-72971

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.