Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for Microsoft August 2026 Patch Tuesday with 400 flaws and 3 zero-days including one actively exploited

Microsoft’s August Patch Tuesday dropped this week with fixes for over 400 vulnerabilities, including one that’s already being exploited and a wormable flaw in Windows DNS Server that should have every IT team’s attention.

The actively exploited bug (CVE-2026-68820) is a use-after-free flaw in the Windows Sockets driver that lets a local attacker escalate to SYSTEM privileges. Microsoft confirmed it’s being used in the wild.

The bigger concern is CVE-2026-62878 — a CVSS 9.8 stack-based buffer overflow in Windows DNS Server. An unauthenticated attacker can send a single crafted packet to trigger remote code execution. No user interaction, no authentication. The Zero Day Initiative has flagged it as potentially wormable, meaning one compromised server could attack others automatically.

Why this matters for Australian businesses

A lot of smaller organisations run Windows Server for Active Directory and don’t think of their DNS role as internet-facing infrastructure. But DNS is a core service, and in the environments we manage across Sydney and regional NSW, the internal DNS server is often the last thing to get patched because it “isn’t public.” If an attacker gets any foothold on your network — a phished credential, a compromised VPN — this flaw becomes an instant path to full server compromise.

What to do now

Check whether your Windows Server instances are running the DNS role. Apply the August cumulative update. If you can’t patch immediately, restrict DNS traffic to trusted sources and monitor for unusual query patterns.

If you’re not sure whether your servers are current, talk to your IT provider — or get in touch with us.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →