CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 1

unknownknown exploitedpublic exploitCVE-2026-33824CVE-2026-55040
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-804 Date: August 11, 2026 Updated: August 18, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows App Installer Application Insights Profiler Azure Active Directory Azure Confidential Ledger Azure CycleCloud Azure Kubernetes Service Azure Logic Apps Azure Monitor Agent Linux Extension Azure SQL Database Azure SQL Managed Instance Azure SRE Agent Azure Service Bus Azure Storage Explorer Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Admin Center Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Defender for Endpoint for Mac Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Business Central 2024 Microsoft Dynamics 365 Business Central 2026 Microsoft Dynamics 365 Business Central Release Wave 1 2025 Microsoft Dynamics 365 Business Central Release Wave 2 2025 Microsoft Entra Connect Microsoft Entra ID Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Mac 2024 Microsoft Outlook 2016 Microsoft Planetary Computer Pro (GeoCatalog) Microsoft Power Apps Microsoft PowerPoint 2016 Microsoft Purview eDiscovery Microsoft SharePoint Enterprise Server 2016 Microso

CSIRTS triage

What
Multiple vulnerabilities affect a broad range of Microsoft products and platforms.
Who is affected
Numerous Microsoft products across .NET, Azure services, and Office components on Linux, macOS, and Windows are affected.
Urgency
Moderate-to-high—the large number of affected components warrants prompt review and patching.
Action
Review the August 2026 monthly rollup advisory and apply patches to affected products according to your deployment inventory.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-18
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-33824coverage & exploitation statusNVD · CVE.org
CVE-2026-55040coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security