
Fixed ``critical'' severity vulnerabilities in Windows, Exchange, etc., urgent application requested
AI-generated summary
Microsoft releases monthly security updates and fixes vulnerabilities in multiple products.
Microsoft has confirmed that it has confirmed that it has been exploited before it is publicly available for one vulnerability, CVE-2026-68820, which is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock.
WinSock (Windows Sockets) refers to the API used by Windows applications to perform network communication. This driver is responsible for the communication processing.
According to Microsoft's Security Update Guide, CVE-2026-68820 is caused by a Use After Free memory. An exploit can be exploited by an authenticated attacker running a specially crafted application in the local environment, causing a race condition. An attacker who successfully exploits this vulnerability can gain SYSTEM privileges. No user interaction required.
Microsoft rates the attack complexity as "high" because exploitation requires a race condition to occur. This is an elevation of privilege vulnerability, which requires an attacker to be able to execute code on the target device in order to exploit it. Still, Microsoft is asking for the update to be applied as soon as possible, saying it has confirmed exploits in the real world.
Which products are âemergencyâ?
The product groups with the maximum severity level of "Urgent" and the expected greatest impact are as follows. For Windows Server, Server Core installation is also included.
Product Family Maximum Severity Most Impact Windows 11 (v26H1, v25H2, v24H2, v23H2) Critical Remote code execution possible Windows Server 2025 Critical Remote code execution possible Windows Server 2022 Critical Remote code execution possible Windows Server 2019, 2016 Critical Remote code execution possible Microsoft Office Critical Remote code execution possible Microsoft Exchange Emergency Remote code execution possible
The maximum severity level was ``Important'' for ``Microsoft SQL Server,'' ``Microsoft Dynamics 365,'' ``Microsoft Azure,'' ``Microsoft .NET,'' ``Microsoft Visual Studio,'' and ``Microsoft Defender.'' Among these, the biggest impact is privilege escalation for Azure, information leakage for Defender, and remote code execution for the others.
When deploying Exchange updates, you should also refer to Microsoft's separate deployment guidance.
Regarding this month's update, Microsoft also announced the following three points.
Known issues for the update are listed in the August 2026 Security Update Release Notes. The security bulletin for Microsoft Edge (Chromium version) has a different publication schedule than the monthly release, so you need to check the security update guide separately. The latest servicing stack update (SSU) can be found in advisory "ADV990001".
The next security update is scheduled to be released on September 8, 2026 (US time).
AI outlook â possibilities, not facts
Next security update release
Very likely · Within weeks

OpenAIã¯AIå°å ¥ã®äŸ¡å€ãããŒã¯ã³å䟡ã§ã¯ãªããæ¥åææãšç·è²»çšããæž¬ãã¹ããšæå±ãGPT-5.6ã·ãªãŒãºã®æå ¥ãéããæšè«å¹çãšä¿¡é Œæ§ãé«ããçµç¹ãAIæè³ã®çµæžæ§ãæå€§åããããã®4ã€ã®è©äŸ¡ææšãæç€ºããã

å 霢ã«ããèªç¥ã»èº«äœæ©èœã®è¡°ãã§ã¹ããŒããã©ã³ã諊ãããã¹ãããªã¿ã€ã¢ãã確èªããã80代ã®ç¯ç®ãäžå¿ã«çŽ6人ã«1人ã«åã¶ãšæšæž¬ããããé¢ããŠæ®ããé«éœ¢ã®èŠªãšã®é£çµ¡ææ®µãšããŠããã¬ãé»è©±ãµãŒãã¹ãªã©ã®ä»£æ¿çãæ³šç®ãããŠããã
ããžã¿ã«ã³ããŒã¹ã¯ãæäººåãAIäœåã®çæã»å ¬éããã¡ã³ãšã®æ¥ç¹äœããã§ããæ°ãµãŒãã¹ãFANZAã¹ã¿ãžãªãã®å è¡äœéšã24æ¥ããéå§ãããšçºè¡šãããéåœOnoma AIãããŒãããŒãšããŠååããã
æ±äº¬éœãšGovTechæ±äº¬ã¯8æ20æ¥ãé²çœãæãææ°ãªã©10çš®é¡ã®éœæ°åãå°å³æ å ±ã1ã€ã«éçŽã»çµã¿åãã衚瀺ã§ããWebãµã€ããTokyo Mapãã®æ£åŒçãå ¬éãããPCãã¹ããããç¡æã§å©çšå¯èœã
LINEã€ããŒã¯8æ20æ¥ãLINEã¢ããªã®çãããã®äžéšã§ã¡ãã¥ãŒã¢ã€ã³ã³ãããã©ã«ãã«ãªãäžå ·åã«ã€ããŠè¬çœªããçµç·¯ãšå¯Ÿå¿ãçºè¡šãããiOSã®æ°ãã¶ã€ã³ä»æ§ãžã®é©å¿ãåå ã§ã幎å ãã9æäžæ¬ã«ãããŠé 次èªå倿ãè¡ãã»ãã察象ãŠãŒã¶ãŒãžã®è¿éãåãä»ããã
SNSäžã®æ å ±ãAIã§åéã»å¯èŠåããã¹ãã¯ãã£ã®ãSpectee Proãã«ã€ããŠè§£èª¬ãçœå®³æã®æ å ±æºãšããŠèªæ²»äœãå ±éæ©é¢ã§æŽ»çšãããŠããããããåœæ å ±ãæé€ããä»çµã¿ã§å±æ©ç®¡çãæ¯æŽããŠããã