We use cookies on this website.

By clicking "Accept," you agree to the storage of cookies on your device to improve your browsing experience, analyze site usage, and contribute to our marketing efforts. See our privacy policy for more information.

Cybersecurity

Windows: 398 vulnerabilities fixed in August—which ones should SMBs really patch?

Microsoft patched nearly 400 Windows vulnerabilities during its August 2026 Patch Tuesday, including two zero-day vulnerabilities and a QUIC vulnerability rated 9.8/10. Not all of them are equally serious. Here’s how to prioritize them when managing an SMB running Microsoft.

Windows: 398 vulnerabilities fixed in August—which ones should SMBs really patch?

In summary: On August 12, 2026, Microsoft released a batch of patches addressing nearly 400 vulnerabilities, including a QUIC flaw rated 9.8/10 and a zero-day vulnerability that had already been exploited. For an SME, the challenge isn’t to patch everything in a single day, but to determine the correct order in which to do so.

What Happened

On August 12, 2026, Microsoft released its monthly Patch Tuesday update. It addresses 398 vulnerabilities, including 44 classified as critical and two zero-days. These figures are taken from Microsoft security bulletins, as reported by the SANS Internet Storm Center, Help Net Security, and CrowdStrike.

Two vulnerabilities stand out from the rest. The first, designated CVE-2026-62815, affects Microsoft’s implementation of QUIC, the protocol that carries HTTP/3. Rated 9.8 out of 10, it allows an unauthenticated attacker to execute code remotely via a single network packet, without any user interaction. It affects Windows 11 and Windows Server 2022 and 2025. The second, CVE-2026-68820, targets afd.sys, the driver that manages network connections in Windows. It is already being exploited in the wild, making it a high priority even though its raw score is lower.

Does this apply to me?

If your workstations are running Windows 11 and your servers are running Windows Server 2022 or 2025, the answer is yes. The afd.sys zero-day vulnerability affects nearly all recent Windows machines, as it targets a core networking component. The QUIC vulnerability primarily exposes servers that publish an HTTP/3 or QUIC service to the outside world: a workstation isolated behind a firewall remains difficult to compromise, whereas a server exposed to the Internet is much more vulnerable.

To assess your risk, check the date of the last patch deployment across your infrastructure and identify the servers that are accessible from the Internet. That's where the exposure becomes real.

What to Do Now

First, address the vulnerability that is already being exploited. CVE-2026-68820 is actively being exploited: apply the afd.sys patch as a priority on workstations and servers, because the risk is real, not theoretical.

Next, patch the exposed servers. Any server that exposes a QUIC or HTTP/3 service to the outside must receive the CVE-2026-62815 patch as soon as possible. Pending deployment, a non-essential service can be temporarily shut down.

Finally, plan the rest. The other patches should be deployed according to your usual cycle, following a quick test on a pilot batch to prevent regressions. Regular patch management is, in fact, one of the measures required by the NIS2 Directive for affected entities. If your IT infrastructure is managed by a third party, ask your service provider for a written update on these two CVEs: which systems are covered, by what date, and what remains to be done.

‍

Not sure about your exposure?

Get an update from an IT Systems expert

A quick assessment of your exposure and the steps you should take. No obligation.

Request an exchange

‍

In a nutshell

A busy Patch Tuesday isn't a cause for panic. Two vulnerabilities deserve your attention this week: the afd.sys zero-day, which is already being exploited, and the QUIC vulnerability on your exposed servers. The rest follows your normal cycle. With a well-monitored infrastructure and an orderly deployment process, this type of month can be handled without any drama.

— Samir Amara, CEO — IT Systèmes

Frequently asked questions

Should we patch everything right away? No. We prioritize addressing the vulnerability that’s already being exploited and the exposed servers, then handle the rest according to the usual schedule after a pilot test.

Is an office workstation behind a firewall vulnerable to the QUIC vulnerability? Much less so than a server exposed to the Internet, but it should still be updated as part of the normal deployment process.

How can I tell if my servers are using QUIC? Check which services are published over HTTP/3 and ask your IT team or service provider for a list of the exposed ports and protocols.

Our latest articles

See more

ASP: The Data Breach Explained, and What an SME Should Check Immediately Afterward

The Services and Payment Agency (ASP) has confirmed a data breach affecting more than 143,000 recipients of the “Coup de pouce énergie” assistance program, with IBANs and Social Security numbers exposed. For an SME, this incident highlights a risk that is easy to check internally: a vulnerability in document access that a public or private website may have without realizing it.
September 25, 2026
AI and Cybersecurity Illustration
Cybersecurity

AI and Cybersecurity: The 3 Key Challenges for SMEs and Mid-Sized Companies

AI and Cybersecurity: Securing Your Use of AI, Using It to Defend Yourself, and Countering AI-Powered Attacks. A Guide for Small and Medium-Sized Businesses.
September 25, 2026
Illustration of an agent-based infrastructure operator
Cybersecurity

Agent-Based Infrastructure Operator: Definition and Role

An agent-based infrastructure operator designs, secures, and continuously operates the layer that enables AI agents to act within the information system. Definition, components, a Microsoft 365 example, and eight questions to help you choose an operator.
September 24, 2026
Illustration: iA Agent
Cybersecurity

Agent-Based AI: Definition, How It Works, and Applications

Agent-based AI refers to AI systems capable of pursuing a goal autonomously: they gather information, plan steps, take action within software, and adjust their plan based on the outcome. Definition, operation, risks, governance, and business applications.
September 24, 2026
Abstract illustration of cybersecurity
Cybersecurity

Brevo: The Data Breach Explained, and What an SME Should Check Immediately Afterward

Brevo, the French email marketing platform used by tens of thousands of small and medium-sized businesses, suffered two security incidents in early September 2026: a breach via an authentication vulnerability, followed by the theft of a technical key that allowed malicious code to be injected into client websites. This week, Trezor and Paymium confirmed the extent of the impact on their users. Here’s what an SME that uses Brevo—or one of its widgets—needs to check.
September 24, 2026
Illustration: Protecting Your Small Business from Cyber Threats
Cybersecurity

How to Protect Your Small Business from Cyberattacks in 2026

Technical prevention, business continuity planning (BCP)/disaster recovery planning (DRP), and cyber insurance: the three lines of defense to protect your small business from cyberattacks in 2026.
September 24, 2026