On August 11, 2026, Microsoft released patches for 394 vulnerabilities at once. That's not a mistake, and it's not even a record for the year — it's simply this month's number.

Among all those CVEs, one stands out for being genuinely dangerous: CVE-2026-68820, a Windows kernel zero-day used by the Lazarus Group — a nation-state hacking operation affiliated with North Korea — to deploy a rootkit. A second one worth knowing about is CVE-2026-70329, a critical flaw rated 8.8 on the CVSS scale that lets an attacker run arbitrary code remotely simply by getting someone to open a booby-trapped file attachment.

If you run a small business, none of this has probably crossed your radar. That's exactly why we're writing about it — so you understand why these updates matter for your business, not just for the IT departments of large enterprises.

What Actually Happened This Week

Here's the short version, without the vendor jargon:

Vulnerability What It Means Severity
CVE-2026-68820
Windows kernel zero-day
A flaw in the AFD.sys driver let the Lazarus Group install a rootkit and take full, undetectable control of a system. It was exploited in the wild before Microsoft's fix existed — which is what makes it a zero-day. Exploited
CVE-2026-70329
Outlook / Office RCE
An integer overflow that needs no advanced technique — just someone in your company opening a malicious attachment. Affects Microsoft 365 Apps, Office 2019, Office LTSC 2021/2024, and Outlook 2016. CVSS 8.8
CVE-2026-62911
Exchange Server
Lets a low-privileged attacker steal credentials and send messages on behalf of the victim — useful for convincing follow-up phishing from inside your own domain. High
CVE-2026-62913
Exchange Server
Allows an unauthenticated attacker to trigger a heap overflow and execute arbitrary code remotely on the Exchange Server itself. Critical
CVE-2026-20349
Cisco firewall
An unauthenticated attacker can cause a buffer overflow and take down the firewall that controls your network access — with a single malicious request. High
CVE-2026-26035
Fortinet FortiWeb
A RADIUS authentication wildcard bug that lets an attacker log into any admin account using any credentials, if RADIUS wildcard authentication is configured. Critical

On top of that list: eleven separate Palo Alto Networks vulnerabilities affecting PAN-OS and GlobalProtect (not currently exploited, but now public knowledge), five high-severity flaws across TP-Link routers and mesh systems, and a 9.8 CVSS bypass in VMware's vCenter management plane.

In total, eight different ecosystems had exploitable vulnerabilities disclosed in a single week. Most small and mid-sized businesses use at least three of these products somewhere in their setup — Outlook, a router, a firewall — without necessarily realising it.

IT specialist reviewing a patch management dashboard across dual monitors in a server room — the real security risk isn't the vulnerability, it's not knowing

Why This Is a Business Problem, Not an IT Problem

Nothing here is especially shocking — this is a normal month for Patch Tuesday. Some months Microsoft patches fewer vulnerabilities, some months more. The volume isn't the anomaly. It's the new normal.

The businesses that get hurt by weeks like this are the unlucky ones — specifically, the ones where nobody was watching for these issues and applying the fixes. Attackers don't need to be clever if a publicly known vulnerability sits unpatched for weeks because nobody owns the job of patching it. And "nobody owns the job" is the reality at far more businesses than most owners would guess. Patch management sounds like a trivial checkbox — until there's no one responsible for ticking it, and it quietly becomes your biggest exposure.

What a Business Without a Dedicated IT Team Should Do

You don't need an in-house security team to handle this threat landscape responsibly. A few consistent habits, owned by someone specific, cover most of the risk:

  1. Patch Windows and Exchange first

    These are the most widely deployed and most targeted systems on the list — which is exactly why attackers assume they're the ones left unpatched. Prioritise them over less common software.

  2. Restrict external access to VPN and firewall admin interfaces

    If there's no clear business reason for your firewall or VPN admin panel to be internet-facing, it shouldn't be. Several of this month's most severe flaws are exactly this kind of exposed management interface.

  3. Update firmware on network devices regularly

    Routers, firewalls, and any equipment managed by your ISP need the same discipline as your laptops and servers. Firmware is patched far less consistently than operating systems — which is precisely why attackers target it.

  4. Train people to be suspicious of file attachments

    CVE-2026-70329 is a textbook example: no complex exploit chain, just someone opening a file they shouldn't have. A few minutes of awareness training for staff closes a gap that no patch alone can fully cover.

  5. Keep a current inventory of your assets

    If you don't know exactly what software and hardware your business runs, you can't tell which of this month's 394 vulnerabilities actually apply to you. An asset inventory is the first thing any real patch management process is built on.

None of this is complicated in principle. It's just regular maintenance — and regular maintenance is exactly what gets skipped at companies where patching isn't clearly somebody's job.

What This Means for Managed IT Services

It's fair to say this is the work we do, and we're not shy about it. Patch management, firmware updates, endpoint monitoring, and vulnerability triage aren't add-ons on top of managed IT — they're the core of what managed IT is meant to provide. The value isn't really visible in incident response. It shows up in the fact that most weeks, nothing happens, because the problems get handled before they become incidents.

The numbers back this up: roughly 94% of small businesses now use some form of managed IT services, and security has become the fastest-growing segment within it — growing at close to 18% a year, as the threat landscape outpaces what a generalist or a part-time IT hire can keep up with alone.

If you read the list above and you're not sure whether even one of those five habits is actually in place at your business right now, that uncertainty is worth resolving before the next Patch Tuesday — not after an incident forces the question.

Not sure what's patched, what's exposed, and who's watching for the next vulnerability? We're happy to give you a straight answer now — contact TekyTec.

Frequently Asked Questions

What is Patch Tuesday and why does it matter for small businesses?

Patch Tuesday is the second Tuesday of every month, when Microsoft and other vendors release security fixes for known vulnerabilities. It matters because every unpatched vulnerability is a publicly documented way into your systems — once a patch ships, attackers reverse-engineer it to target anyone who hasn't installed it yet, small businesses included.

What is a zero-day vulnerability?

A zero-day is a vulnerability attackers are already exploiting before the vendor has released a fix, meaning defenders have had zero days to prepare. CVE-2026-68820, the Windows kernel flaw used by the Lazarus Group to install a rootkit, is a zero-day — it was exploited in the wild before Microsoft's patch existed.

Do I need to worry about these vulnerabilities if I don't use Windows servers?

Almost certainly yes. This round of patches spans eight ecosystems — Windows, Outlook and Microsoft 365, Exchange Server, Cisco firewalls, Fortinet, Palo Alto Networks, TP-Link routers, and VMware vCenter. Most small and mid-sized businesses run at least three of these somewhere, even if it's just Outlook and a router.

How quickly should a small business apply security patches?

Critical and actively exploited vulnerabilities — like the Windows kernel zero-day and the Exchange Server flaws here — should be patched within days, not weeks. Once a patch ships, attackers study it and scan the internet for systems that haven't applied it. That gap is exactly where most breaches happen.

What's the difference between patch management and managed IT services?

Patch management is one piece of managed IT. A managed IT provider handles patching across operating systems, network devices, and business applications on a routine schedule, alongside endpoint monitoring, firewall management, and vulnerability triage — ongoing prevention rather than a one-time task dependent on someone remembering.

T
TekyTec IT Solutions

We help small and mid-sized businesses across Tamil Nadu and India stay ahead of exactly this kind of threat — patch management, endpoint monitoring, and vulnerability triage handled as routine maintenance, not emergency response.