Microsoft Deploys August 2026 Patch Tuesday for Windows 11
On August 11, 2026, Microsoft released cumulative updates KB5121003 and KB5120240 for Windows 11, marking the eighth Patch Tuesday of the year. These updates are mandatory: they contain the security patches for August 2026, covering 400 vulnerabilities identified over the preceding months.
- KB5121003 targets 25H2 and 24H2 versions of Windows 11 (the 25H2 version receiving the same fixes as the 24H2, being based on the latter).
- KB5120240 is aimed at the 23H2 version of Windows 11.
To install these updates, users can go to Settings > Windows Update > Check for updates, or manually download the packages from the Microsoft Update Catalog.
A Decrease in the Volume of Fixes Compared to July
Last month, Microsoft set a record with 570 vulnerabilities fixed during the July 2026 Patch Tuesday, including three zero-days (two actively exploited and one publicly disclosed). This was the largest number of flaws ever fixed in a single wave of updates.
This significant drop in August (400 vulnerabilities compared to 570 in July) still constitutes a large volume. Microsoft had warned in July that the increase in the number of fixes was related to the use of an AI-assisted vulnerability discovery system, which identifies more flaws in the Windows source code before attackers can exploit them.
Context Reminder: July's Zero-Days
The three zero-days fixed in July 2026 are worth mentioning, as they illustrate the ongoing exploitation activity on Microsoft products:
- CVE-2026-56155 — A privilege escalation in Active Directory Federation Services (AD FS), actively exploited. Discovered by Microsoft’s DART team, likely during an incident investigation.
- CVE-2026-56164 — A privilege escalation in Microsoft SharePoint Server, actively exploited. Credited to researchers from Mandiant and Google Cloud.
- CVE-2026-50661 — A publicly disclosed BitLocker bypass allowing an attacker with physical access to circumvent encryption.
SharePoint Still Targeted by Ransomware
This context remains relevant: on the same day as the release of these updates, August 11, 2026, CISA (Cybersecurity and Infrastructure Security Agency) confirmed that the vulnerability CVE-2026-45659 in Microsoft SharePoint — a remote code execution flaw due to deserialization of untrusted data — is now actively exploited by ransomware groups. The monitoring group Shadowserver reports over 8,500 exposed SharePoint servers on the internet, of which more than 200 remain unpatched against this vulnerability. Since November 2021, CISA has reported 14 actively exploited SharePoint vulnerabilities, including 8 in the context of ransomware attacks.
New Features and Improvements in August 2026 Patch Tuesday
Most of the improvements introduced in these updates do not activate immediately: Microsoft is conducting a gradual rollout. Several of these changes had already been tested in the preliminary update KB5101684 released on July 29, 2026, which included 42 fixes and enhancements.
File Explorer
- File sizes are now displayed with appropriate units (KB, MB, GB) instead of just showing everything in KB.
- Middle-clicking to open a folder in a new tab is now supported in the address bar and the homepage.
- Fixed a gray flash on loading and an involuntary scroll-up on the homepage.
- Improved thumbnail clarity in the "Recommended" section.
Windows Search
- Application search now better handles typos and partial application names.
- Search results in Settings are more relevant, with better ranking.
Voice Access
- New: Added Voice Isolation for Voice Access, which filters out other speakers and background noise for better voice recognition.
- Three recognition modes available: Voice Isolation (configuration required), Background Noise Suppression only, and No Filtering.
- New: Support for the Korean language in Voice Access.
- Improved reliability for starting Voice Access.
Widgets
- New: Taskbar notification badges now use your Windows accent color instead of red, to reduce overly flashy alerts.
- New: Simplified lock screen: Weather is now the only widget displayed by default for new users.
Precision Touchpad
- New: Gesture controls available in Settings > Bluetooth & devices > Touchpad:
- Adjustable scrolling speed and zoom.
- Accelerated scrolling (the more you repeat the gesture, the faster the scrolling).
Windows Hello
- New: Windows Hello Enhanced Sign-in Security (ESS) now supports external fingerprint sensors. This feature, announced in January 2026 (KB5074105), finally extends to desktop PCs and other Windows 11 devices, including Copilot+ PCs.
Other Notable Improvements
- Start Menu: Improved reliability of display preferences; better keyboard navigation in the application list.
- Accessibility: Enhanced Magnifier on touch devices (touch panning bars are disabled by default).
- Voice Typing: Smooth dictation is now disabled by default for new users.
- Windowing: System dialog boxes open at the appropriate size on small tablets.
- Font: Restored support for Unicode variation sequences in the Myanmar Text font and improved rendering of the Mongolian Baiti font.
- Account Control: Refresh of the account control design in the Start menu, with a badge displaying subscription status (Microsoft account required).
- Energy and Battery: Improved reliability of power setting adjustments (display, sleep, hibernation, power button, lid close) applied to all plans. Restored setting for the energy saver activation threshold.
- Windows Update: Improved update progress calculation and post-update cleanup logic to optimize system performance.
- Date and Time: Updated DST (Daylight Saving Time) data for Beirut, Casablanca, Jerusalem, and Nuuk.
- AI: Ability to remove the Image Generation AI component on compatible Copilot+ PCs.
- Windows Configuration: Added a parental control notice during setup, highlighting family safety features.
No Known Issues at This Time
Microsoft indicates that it is not aware of new issues with this month's updates. In July, the company had to release an out-of-band update (KB5121767) to fix crashes on certain Dell PCs caused by July's security updates. The company also had to block the update on certain Dell devices.
Recommendations
Given the volume of fixed vulnerabilities (400) and the active exploitation of recent Microsoft flaws — particularly the SharePoint vulnerability CVE-2026-45659 now targeted by ransomware — it is strongly recommended to install as soon as possible, whether via Windows Update or the Microsoft Update Catalog.
For enterprise environments, it is advisable to:
- Test updates on a pilot group before a large-scale deployment.
- Check for regressions on Dell PCs, which experienced issues the previous month.
- Monitor exposed SharePoint servers on the internet and ensure they are up-to-date by enabling the AMSI (Antimalware Scan Interface) as a mitigating measure.
In Summary
The August 2026 Patch Tuesday fixes 400 vulnerabilities — a volume lower than the July record (570), but still significant. It also introduces a rich set of functional improvements, several of which were already in testing in the preliminary update KB5101684 from late July. No known issues have been reported so far. In a context where Microsoft flaws are actively exploited by ransomware groups, the rapid deployment of these fixes remains a security priority.