NCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windows
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Microsoft has patched a large number of vulnerabilities in Windows. An attacker can exploit the vulnerabilities to conduct attacks that may result in the damage categories described in the table below. The most severe vulnerabilities have been assigned the identifiers CVE-2026-59124, CVE-2026-62815, CVE-2026-62878, CVE-2026-62893 and CVE-2026-65791 and are located in Telephony Service, QUIC, DNS Server, Capability Access Management Service, and iSCSI Target Service respectively. Attackers with access to these services may be able to execute code or gain access to the vulnerable system without prior authentication. In addition to these severe vulnerabilities, more than 230 vulnerabilities have been patched, all varying in severity from moderate to high/critical. Due to the nature and scope of these updates, the NCSC advises prioritizing the deployment of these updates.
Windows Accessibility Infrastructure (ATBroker.exe): |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-61358 | 7.80 | Privilege escalation | |----------------|------|-------------------------------------| Windows Kernel: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-54113 | 7.50 | Denial-of-Service | | CVE-2026-61930 | 7.80 | Privilege escalation | | CVE-2026-62737 | 7.80 | Privilege escalation | | CVE-2026-61929 | 7.00 | Privilege escalation | | CVE-2026-62708 | 6.40 | Privilege escalation | | CVE-2026-62749 | 7.00 | Privilege escalation | | CVE-2026-62780 | 7.00 | Privilege escalation | | CVE-2026-62788 | 7.00 | Privilege escalation | | CVE-2026-65773 | 7.80 | Privilege escalation | |----------------
CSIRTS triage
- What
- Multiple vulnerabilities in Windows services including Telephony, QUIC, DNS Server, Capability Access Management, and iSCSI Target Service allow code execution or unauthenticated access.
- Who is affected
- Windows deployments running vulnerable versions of the affected services.
- Urgency
- Immediate patching required; vulnerabilities are actively exploited and cover critical services with remote code execution impact.
- Action
- Deploy Microsoft's latest Windows security updates immediately, prioritizing the five named CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows
Get an email when a new Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0284
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-591241.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 75% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628150.92% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628780.91% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-628931.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 76% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657910.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-613583.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-541131.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-619302.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627370.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-619291.5% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 73% of all EPSS-scored CVEs.
Referenced CVEs
+184 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- critical[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilitiescert-bund
- unknownexploitedMicrosoft Monthly Security Update (August 2026)hkcert
- unknownexploitedSecurity Alert: Microsoft Releases August 2026 Security Updatesjpcert
- unknownexploitedMultiple vulnerabilities in Microsoft Windows (August 12, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft Azure (August 12, 2026)cert-fr-avis
- highCVE-2026-71331: Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attest…nvd
- mediumCVE-2026-70348: Improper link resolution before file access ('link following') in Windows Management Services …nvd
- highCVE-2026-70347: Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privi…nvd
- highCVE-2026-70346: Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate priv…nvd
- highCVE-2026-70345: Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privi…nvd
- highCVE-2026-70344: Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate priv…nvd
- mediumCVE-2026-70330: Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges …nvd
Recent advisories for Microsoft Windows
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- critical[NEW] [critical] Microsoft Windows Products: Multiple vulnerabilitiescert-bund · 2026-08-14
- criticalexploited[UPDATE] [critical] Microsoft Windows: Multiple Vulnerabilitiescert-bund · 2026-08-13
- medium[NEW] [medium] Microsoft Windows Package Manager: Vulnerability enables Privilege Escalationcert-bund · 2026-08-12
- unknownexploitedMultiple vulnerabilities in Microsoft Windows (August 12, 2026)cert-fr-avis · 2026-08-12
- mediumCVE-2026-59136: Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to di…nvd · 2026-08-11
- mediumCVE-2026-59135: Weak authentication in Microsoft Windows Search Component allows an authorized attacker to dis…nvd · 2026-08-11
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13