Blackpoint Cyber Threat Notice: August 2026 Patch Tuesday Updates

Overview 

This month’s Patch Tuesday brought 400 vulnerabilities from Microsoft, plus security notes from SAP and security updates from Adobe. Read to learn how Blackpoint is staying ahead and recommended actions.

Microsoft 

Microsoft’s August 2026 Patch Tuesday addressed 400 vulnerabilities, including three zero-day vulnerabilities: one actively exploited in the wild and two publicly disclosed prior to a patch being available. 

CVE-2026-68820 | CVSS 7.8 High | Elevation of Privilege vulnerability impacting Windows Ancillary Function Driver for WinSock  

  • A use-after-free vulnerability in AFD.sys allows a locally authenticated attacker to trigger a race condition and elevate privileges to SYSTEM. No user interaction is required. 
  • Confirmed actively exploited in the wild by the North Korean Lazarus Group. Check Point Research reported the flaw was used to deploy a new version of FudModule, Lazarus’ kernel-mode rootkit. 

CVE-2026-62832 | CVSS 7.8 High | Elevation of Privilege vulnerability impacting Windows User Profile Service 

  • An improper link resolution flaw allows an authenticated attacker to load another user’s registry hive, access or modify that user’s data, and gain administrator privileges. 
  • Publicly disclosed prior to patch availability as ‘LegacyHive.’ No evidence of active exploitation at the time of writing. 

CVE-2026-72971 | CVSS 5.5 Medium | Tampering vulnerability impacting Windows Container Isolation FS Filter Driver  

  • An improper link resolution flaw allows an authenticated attacker to perform local tampering, accessing or modifying another user’s data and gaining administrator privileges. 
  • Publicly disclosed prior to patch availability. No evidence of active exploitation at the time of writing. 

Microsoft also patched hundreds of additional vulnerabilities across Office, Windows, Azure, Exchange Server, and other products this cycle. 

SAP 

SAP’s August 2026 Security Patch Day addressed 28 new security notes, including several critical-severity flaws affecting widely deployed enterprise platforms. 

CVE-2026-58231 | CVSS 10.0 Critical | Improper Authorization vulnerability impacting SAP Commerce Cloud  

  • A maximum-severity improper authorization flaw affecting COM_CLOUD versions 2211 and 2211-JDK21. Exploitation requires no prior privileges or user interaction. 
  • Successful exploitation grants remote attackers’ complete control over confidentiality, integrity, and availability. There is no evidence of active exploitation at the time of writing. 

CVE-2026-34265 | CVSS 9.8 Critical | Memory Corruption vulnerability impacting SAP NetWeaver and ABAP Platform 

  • A memory corruption bug in the Application Server ABAP component affecting kernel versions 7.22 through 9.19. Memory corruption flaws in core application servers can be weaponized to achieve remote code execution. 
  • There is no evidence of active exploitation at the time of writing; however, SAP platforms are a recurring target for ransomware operators and nation-state actors. 

Adobe 

Adobe released security updates for multiple products in August 2026, including critical vulnerabilities impacting ColdFusion and Lightroom Classic. 

CVE-2026-48362 | CVSS 10 Critical | Arbitrary code execution impacting Adobe ColdFusion 

  • Allows remote attackers to execute arbitrary code without user interaction or privileges. 

CVE-2026-48273 | CVSS 9.9 Critical | Arbitrary code execution impacting Adobe ColdFusion  

  • Successful exploitation requires user interaction, specifically, a victim opening a malicious file, and can lead to arbitrary code execution. 

ColdFusion has been a sustained target through 2026, with a prior critical flaw (CVE-2026-48282, CVSS 10.0) exploited within two hours of public disclosure in June 2026. Adobe has not reported active exploitation of these specific vulnerabilities at the time of writing. 

CVE-2026-48441 | CVSS 8.6 High | Path Traversal vulnerability impacting Adobe Lightroom Classic 

  • A path traversal vulnerability in Lightroom Classic 15.4 and earlier that could result in arbitrary code execution. This is the highest-severity issue in the Lightroom Classic advisory. 
  • Adobe has not identified any exploits in the wild for this issue at the time of writing. Users should update to Lightroom Classic 15.5 via the Creative Cloud desktop app. 

Adobe also released patches for vulnerabilities impacting Commerce, Content Credentials SDK, and Campaign Classic.  

What is Blackpoint doing? 

As the threat landscape shifts, Blackpoint stays ahead by building and deploying real-time detections tuned to the latest adversary tradecraft. When threats are identified, Blackpoint takes decisive action by hunting down and actioning every associated IOC across customer environments before attackers can establish a foothold or move laterally. 

Recommendations 

  • Immediate Action: Apply the August 2026 Patch Tuesday updates immediately. 
  • Restrict administrative and remote access to trusted users and networks. 
  • Enforce MFA to reduce risk from stolen or reused credentials. 
  • Restrict internet exposure of SAP Commerce Cloud and NetWeaver administrative interfaces. 
  • Prioritize patching of ColdFusion instances, particularly any internet-facing deployments, given the product’s recent exploitation history. 
  • Review EDR, IDS, and vulnerability scanning coverage across affected assets. 

References 

DATE PUBLISHEDAugust 11, 2026
AUTHORAndi Ursry

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY