Microsoft security updates
Microsoft Security Patch Roundup — Week of August 28, 2026
Official Microsoft Security Response Center updates published during the past week, collected for patch planning and review.
Published 28 August 2026 · RCW IT Training
Important: Review the linked Microsoft advisory, affected-product information and available mitigations before deployment. This roundup is an index of official notices, not a substitute for change testing or incident response guidance.
Official MSRC updates
- CVE-2026-70329 Microsoft Outlook Remote Code Execution Vulnerability (27 Aug 2026)
- CVE-2026-69550 Windows App for Mac Information Disclosure Vulnerability (27 Aug 2026)
- CVE-2026-68817 Microsoft Excel Remote Code Execution Vulnerability (27 Aug 2026)
- CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability (27 Aug 2026)
- CVE-2026-65779 Windows Autopilot Elevation of Privilege Vulnerability (27 Aug 2026)
- CVE-2026-65660 Microsoft SharePoint Server Remote Code Execution Vulnerability (27 Aug 2026)
- CVE-2026-50435 Windows Overlay Filter Elevation of Privilege Vulnerability (27 Aug 2026)
- CVE-2026-50351 Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability (27 Aug 2026)
- CVE-2026-42993 Remote Desktop Client Remote Code Execution Vulnerability (27 Aug 2026)
- CVE-2026-68819 Windows Network File System Denial of Service Vulnerability (26 Aug 2026)
- CVE-2026-62890 Windows GDI+ Elevation of Privilege Vulnerability (26 Aug 2026)
- CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability (20 Aug 2026)
Recommended next steps
- Identify affected assets and confirm update applicability.
- Prioritise actively exploited or internet-facing risk according to your organisation’s process.
- Test patches in a representative ring, deploy in approved windows and verify service health.
- Record exceptions, mitigations and the next review date.