Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-804 Date: August 11, 2026 Updated: August 18, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows App Installer Application Insights Profiler Azure Active Directory Azure Confidential Ledger Azure CycleCloud Azure Kubernetes Service Azure Logic Apps Azure Monitor Agent Linux Extension Azure SQL Database Azure SQL Managed Instance Azure SRE Agent Azure Service Bus Azure Storage Explorer Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Admin Center Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Defender for Endpoint for Mac Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Business Central 2024 Microsoft Dynamics 365 Business Central 2026 Microsoft Dynamics 365 Business Central Release Wave 1 2025 Microsoft Dynamics 365 Business Central Release Wave 2 2025 Microsoft Entra Connect Microsoft Entra ID Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 Microsoft Outlook 2016 Microsoft Planetary Computer Pro (GeoCatalog) Microsoft Power Apps Microsoft PowerPoint 2016 Microsoft Purview eDiscovery Microsoft SharePoint Enterprise Server 2016 Microso
CSIRTS triage
- What
- Multiple vulnerabilities affect a broad range of Microsoft products and platforms.
- Who is affected
- Numerous Microsoft products across .NET, Azure services, and Office components on Linux, macOS, and Windows are affected.
- Urgency
- Moderate-to-high—the large number of affected components warrants prompt review and patching.
- Action
- Review the August 2026 monthly rollup advisory and apply patches to affected products according to your deployment inventory.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-33824Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.5% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-55040Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 92% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-33824 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55040 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Four Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerabilitycisa-kev
- criticalexploitedCVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerabilitycisa-kev
- unknownexploitedNCSC-2026-0237 [1.02] [H/H] Vulnerabilities Fixed in Microsoft Officencsc-nl
- unknownexploitedNCSC-2026-0237 [1.01] [H/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- criticalexploitedAL26-017 - Critical vulnerabilities impacting Microsoft SharePoint Server – CVE-2026-56164, CVE-2026-55040 and…cccs
- unknownexploitedNCSC-2026-0237 [1.00] [M/H] Vulnerabilities fixed in Microsoft Officencsc-nl
- criticalCVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a…nvd
- unknownexploitedCISA Urges SharePoint Hardening After New Exploitationscisa
- criticalCVE-2026-55040: Microsoft SharePoint Server Security Feature Bypass Vulnerabilitymsrc
More from Canadian Centre for Cyber Security
- unknownCitrix security advisory (AV26-833)2026-08-19
- unknownMLflow security advisory (AV26-832)2026-08-19
- criticalOracle Corporation security advisory (AV26-831)2026-08-19
- unknownNVIDIA security advisory (AV26-830)2026-08-19
- unknownAtlassian security advisory (AV26-829)2026-08-19