Microsoft’s August 2026 Patch Tuesday fixed a critical Microsoft 365 Admin Center vulnerability with a 9.8 severity score, and if your business runs Microsoft 365, that particular fix already applied itself on Microsoft’s side. What you still control is your own exposure: device patching, admin account hygiene, and how fast your team reacts when a fix like this lands. Southwest Florida businesses that treat Patch Tuesday as a monthly afterthought are the ones most likely to get caught out.
- Microsoft patched 421 vulnerabilities in August 2026, including 62 rated critical.
- CVE-2026-62873, a critical elevation-of-privilege flaw in the Microsoft 365 Admin Center, scored 9.8 out of 10 and was fixed on Microsoft’s cloud side.
- A separate zero-day, CVE-2026-68820, was already being exploited by a North Korea-linked group before the patch shipped, and it targets Windows devices directly.
- Cloud-side fixes don’t cover your laptops, servers, and VPN gateways; those still need your IT team or provider to apply updates.
- Slow patching remains one of the most common root causes behind small business breaches.
What is CVE-2026-62873 and does it affect my business?
CVE-2026-62873 is an elevation-of-privilege vulnerability in the Microsoft 365 Admin Center caused by improper verification of a cryptographic signature. The National Vulnerability Database entry lists a CVSS base score of 9.8, near the top of the severity scale, and the flaw was published on August 6, 2026. Because the Admin Center is a cloud service, Microsoft applied the fix on its end and you don’t need to install anything for this specific flaw. What it should do is prompt a review of who in your organization holds Global Administrator or other privileged roles in Microsoft 365. As we covered in our 2026 Microsoft 365 cybersecurity checkup, trimming unnecessary admin access is one of the highest-value changes you can make in fifteen minutes.
Why did this Patch Tuesday get so much attention?
August’s release was unusually large. SecurityWeek reported that Microsoft addressed 421 CVEs in total, with 62 rated critical, one of the bigger monthly totals in recent memory. One of those flaws, CVE-2026-68820, was already being used in real attacks before the patch went out. Researchers at Check Point traced exploitation of that bug to a North Korea-linked group running a campaign known as Operation Dream Job, and Help Net Security’s coverage describes it as a local privilege escalation flaw in a core Windows networking driver, used to install a kernel-level rootkit after an initial compromise. That one does require action on your part: it’s an operating system patch, not a cloud-side fix, so any PC or server that missed its update cycle in mid-August is still exposed.
What should a small business actually do this week?
Start by confirming your endpoint management tool, whether that’s Intune, an RMM platform, or manual Windows Update, has pushed and installed the August cumulative update on every device. Check servers separately, since they often sit on a slower patch schedule than workstations. Then review Microsoft 365 admin roles: remove anyone who no longer needs elevated access, and confirm multi-factor authentication is turned on for every account that has it available. If you outsource IT, ask directly whether the August patches are confirmed installed across your fleet, not just scheduled for installation.
How does this connect to hurricane season readiness?
Southwest Florida businesses already track storm prep on a calendar. Patch verification deserves the same discipline, because a device left unpatched during a storm evacuation or office closure is a device an attacker has extra time to find. If your team is already working through patch management practices ahead of hurricane season, folding a monthly Patch Tuesday check into that routine closes an easy gap.
Frequently asked questions
Do I need to do anything about CVE-2026-62873 myself?
No direct action is needed for that specific flaw, since Microsoft patched it in the cloud service. Use it as a prompt to audit who holds admin access in your Microsoft 365 tenant.
What is Patch Tuesday?
Patch Tuesday is Microsoft’s regular monthly release of security updates, issued on the second Tuesday of each month, covering Windows, Office, Exchange, and other Microsoft products.
Is the zero-day, CVE-2026-68820, a risk to a typical small office?
Yes, if a device is running an unpatched version of Windows. It requires an attacker to already have some level of access to the machine, but it has been used in real attacks, so timely patching closes that door.
How often should we check that patches actually installed, not just downloaded?
Monthly at minimum, tied to Microsoft’s release schedule. A quick device check after each Patch Tuesday catches machines that were off, asleep, or skipped during the automatic update window.
If you’re not certain every device in your office is current on August’s updates, or you want a second set of eyes on your Microsoft 365 admin access, SWFIT offers a free 15-minute IT and security review. Contact us to schedule one.