Microsoft shipped its August 2026 Patch Tuesday update on August 11, ending a run of bulletins that security teams are still sorting through nearly three weeks later. The update fixes at least one vulnerability that attackers were already exploiting before Microsoft had a patch ready, plus two more that were publicly disclosed but not yet weaponized. That much, every vendor agrees on. What they can’t agree on is how many bugs actually shipped in the batch. Depending on which security firm you ask, the number ranges from 398 to 751, a gap of 353 CVEs for the same monthly release.

That’s not a rounding error. It’s a sign that “Patch Tuesday” no longer means one clean, countable event. It means seven or eight different accounting methods layered over the same set of Microsoft security bulletins, each one built for a different audience: patch-management vendors selling prioritization tools, cloud posture platforms tracking their own scope, and researchers counting individual CVE identifiers rather than the KB articles IT teams actually install. This piece walks through what shipped, why the count keeps splitting apart, and what security teams should be doing about it right now.

The One Number Every Vendor Agrees On: An Active Zero-Day

BleepingComputer‘s August 11 write-up put the headline plainly: the release fixes roughly 400 flaws, including one vulnerability already being exploited in the wild and two more that were publicly disclosed ahead of the patch. Tenable‘s research team, publishing six days later on August 17, confirmed the same shape of the story: three zero-days total, one of them already under active attack. CrowdStrike‘s analysis, out on August 20, lines up too, one exploited zero-day and three disclosed zero-days sitting inside a batch of 415 vulnerabilities.

None of the three outlets published the specific CVE identifier tied to the actively exploited bug in the passages reviewed for this piece, which is itself a useful data point. The emergency-patch signal, something is already being used against real networks, traveled faster and cleaner across the industry than the actual bug inventory did. Security teams triaging this release inside the first 48 hours were working off headlines, not spreadsheets.

Seven Vendors, Seven Different CVE Totals

Here’s where the story gets messy. Lay the vendor reports side by side and the total CVE count swings by more than 350, depending entirely on what each outlet chose to count.

SourceReported totalCritical-ratedWhat’s actually being countedPublished
BleepingComputer~400 flawsNot broken outMicrosoft vulnerabilities, roundedAug 11, 2026
Tenable398 CVEs42Microsoft CVEs onlyAug 17, 2026
Ivanti398 CVEs42Microsoft CVEs onlyAug 11, 2026
Qualys421 vulnerabilities62Microsoft + Adobe combinedAug 11-13, 2026
Rapid7421 vulnerabilitiesNot broken outMicrosoft only, 236 in Windows aloneAug 2026
CrowdStrike415 vulnerabilities62Microsoft’s own release scopeAug 20, 2026
Lansweeper669 fixes82Per-KB fix count, not per-CVEAug 2026
Senserva / Computerworld751 CVE entries108Every CVE touched across all product familiesAug 2026

Notice the pattern: Tenable and Ivanti land on the exact same 398/42/355/1 split, which suggests both firms are pulling from the same underlying Microsoft-only dataset rather than independently auditing the release. Qualys and Rapid7 both report 421, but for different reasons. Qualys folds in Adobe’s same-day patches under one combined “Microsoft and Adobe Patch Tuesday” banner, while Rapid7 appears to be counting a broader slice of Microsoft’s own catalog. Lansweeper and Senserva/Computerworld are playing an entirely different game, counting KB-level fixes and cross-product CVE entries rather than the CVEs Microsoft assigned this specific month.

Why the Same Patch Batch Produces Wildly Different Counts

Three separate counting decisions explain almost the entire gap. First, scope: does the count include only CVEs where Microsoft is the assigning authority, or does it fold in Adobe and other vendors that happen to patch on the same Tuesday? Qualys says yes to the latter; Tenable, Ivanti, and CrowdStrike say no. Second, unit of measurement: a “fix” and a “CVE” aren’t the same thing. One KB article can resolve several CVEs at once, which is how Lansweeper arrives at 669 while sitting closer to the Microsoft-only crowd on critical-severity math. Third, and least visible to outsiders, is whether a vendor counts every CVE entry touched across Microsoft’s entire product portfolio, including older, extended-support branches, or only the CVEs newly disclosed this month. That’s almost certainly what pushes Senserva and Computerworld up to 751.

None of this is dishonest reporting. Each vendor is answering a slightly different question for a slightly different customer. But it does mean a CISO pulling headlines from three sources on the same Tuesday morning can walk away with three different risk pictures, and that’s a real operational problem when the size of the patch batch is supposed to inform how much engineering time gets pulled off other work this sprint.

CVE-2026-62878: The Windows DNS Server Bug Called “Technically Wormable”

Buried inside the count discrepancy is one bug that deserves attention regardless of how you tally the total. TechRepublic‘s coverage of the release, published around August 13, singles out CVE-2026-62878, a stack-based buffer overflow in Windows DNS Server. The Zero Day Initiative describes it as technically wormable, meaning a working exploit could in theory spread from one vulnerable DNS server to another without a human clicking anything in between.

What “Wormable” Actually Means for IT Teams

Wormable doesn’t mean an active worm exists today. It means the vulnerability class, remote code execution with no required authentication or user interaction on a network-facing service, matches the pattern that historically produced self-propagating malware. DNS servers are also unusually exposed by design. They have to answer requests from across a network, which limits how aggressively they can be firewalled off. That combination is why security teams tend to move DNS-server RCE bugs to the top of the patch queue even when Microsoft hasn’t rated them the single highest severity in the batch.

Three More Bugs Security Teams Are Racing to Close

CVE-2026-62878 wasn’t traveling alone. TechRepublic’s review named three additional remote-code-execution bugs from the same release that require no user interaction to trigger.

CVE IDAffected componentBug typeNotable detail
CVE-2026-62878Windows DNS ServerStack-based buffer overflow, RCECalled “technically wormable” by the Zero Day Initiative
CVE-2026-62893Windows Deployment Services TFTP serverRemote code executionGrouped among no-interaction-required critical bugs
CVE-2026-62815Microsoft QUICRemote code executionAffects the transport protocol layer, not a single app
CVE-2026-59124Microsoft HPC PackRemote code executionRated Important, not Critical, because HPC Pack isn’t installed by default

The One Bug That’s Serious But Not “Critical”

CVE-2026-59124 is a useful reminder that Microsoft’s severity labels reflect exposure as much as raw exploitability. TechRepublic notes it was rated Important rather than Critical specifically because HPC Pack, a high-performance computing add-on, isn’t part of a default Windows install. Fewer machines run it, so the blast radius shrinks even though the underlying flaw is a remote code execution bug. Organizations that do run HPC clusters, common in research computing and financial modeling shops, shouldn’t read “Important” as “skip it.”

Which Microsoft Products Took the Hit

Between the Qualys and Splashtop write-ups, the affected product list spans most of Microsoft’s core stack: Windows itself (HTTP.sys, Hyper-V, NTFS, and Desktop Window Manager all got fixes), Microsoft Exchange Server, SharePoint Server, Office, Azure services, Microsoft Defender, Dynamics Business Central, and developer tooling including Visual Studio Code and GitHub Copilot. Rapid7 put a finer point on the Windows-specific load, counting 236 vulnerabilities inside Windows alone this cycle.

The developer-tooling entries are worth pausing on. Visual Studio Code and GitHub Copilot showing up in a monthly security bulletin is a fairly recent pattern, and it tracks with how much of the developer toolchain has shifted into cloud-connected, AI-assisted software over the past two years. A vulnerability in a coding assistant doesn’t just risk one machine, it risks whatever code that assistant touches across a team.

Checking Your Own Patch Status

Regardless of which vendor’s total you trust, the practical first step is the same: confirm the August 2026 cumulative update actually installed. On a single Windows machine, a quick PowerShell check against installed hotfixes gives a fast answer before pulling a full compliance report from WSUS, Intune, or SCCM.

Get-HotFix | Where-Object { $_.InstalledOn -ge (Get-Date "2026-08-11") } |
  Select-Object HotFixID, Description, InstalledOn |
  Sort-Object InstalledOn -Descending

For fleet-wide checks, cross-reference the KB numbers returned against Microsoft’s own Security Update Guide, which remains the single source of truth for which CVEs map to which KB article, something none of the third-party summaries fully replace.

Vulnerability Vendors Are Turning Patch Tuesday Into a Marketing Cycle

The competing CVE counts aren’t just a data-quality quirk, they’re also a market signal. Every major vulnerability-management vendor now races to publish its own Patch Tuesday breakdown within hours of release, each framed to showcase its own scanning and prioritization engine. A 2026 category comparison from Orca Security lists Tenable Nessus, Qualys, OpenVAS, Nuclei, Trivy, and ZAP among the tools actively being weighed against each other by buyers this year, spanning everything from deep credentialed host scanning to container and Kubernetes-focused checks.

That competitive pressure is exactly why the numbers diverge instead of converging. A vendor whose product scans Adobe alongside Microsoft has a reason to report the combined total. A vendor whose value proposition is “we tell you what matters inside Microsoft’s own release” has a reason to keep the count narrow and clean. Neither is lying. Both are optimizing for the story that sells their tool. Related patch-management pressure has been building all month, from the Kubernetes Ingress-Nginx flaw still sitting unpatched at CVSS 8.8 to the cPanel auth-bypass bug hitting 1.5 million servers, both of which kept enterprise patch teams busy well before Microsoft’s own release landed.

A Short History of How Patch Tuesday Got This Big

Microsoft consolidated its security updates into a single monthly release, the second Tuesday of each month, back in October 2003, largely to give IT departments a predictable schedule instead of a constant drip of ad hoc patches. Two decades on, the cadence hasn’t changed, but the surface area has grown enormously. Azure, Microsoft 365, Dynamics, and an expanding set of AI-integrated developer tools have all been folded into the same monthly cycle that used to cover little more than Windows and Office. A single Patch Tuesday today effectively bundles security maintenance for a cloud platform, a productivity suite, a developer ecosystem, and a traditional desktop OS, which is a large part of why counting the bugs inside it has become its own specialized exercise.

Why the Counting Mess Actually Matters for Enterprise Security Teams

A 353-CVE swing between the lowest and highest reported total isn’t just an academic disagreement. Security teams use these monthly totals to size the patch cycle, budget testing time, and brief leadership on how urgent the month’s work is. A team reading Tenable’s 398 might staff the week differently than a team reading Computerworld’s 751, even though both are describing the same underlying release. That mismatch pushes some organizations toward a defensible middle ground: patch to the exploited zero-day and Critical-rated bugs immediately, and treat the exact total CVE count as a secondary, vendor-dependent detail rather than the number that drives triage. It’s a similar lesson to the one enterprises learned from this year’s 49% jump in active ransomware groups, where the raw headline number mattered less than which specific group was targeting a given sector.

What to Patch First: A Practical Priority Order

Given the confirmed facts across BleepingComputer, Tenable, and CrowdStrike, a reasonable triage order looks like this:

  • Confirm the exploited-in-the-wild zero-day is patched everywhere internet-facing systems touch Windows, since this is the one bug all three outlets agree is already being used against real targets.
  • Prioritize CVE-2026-62878 (Windows DNS Server) on any server running the DNS role, given the “technically wormable” characterization from the Zero Day Initiative.
  • Move CVE-2026-62893 and CVE-2026-62815 up the queue on Windows Deployment Services and QUIC-dependent infrastructure.
  • Don’t skip CVE-2026-59124 just because it’s rated Important if HPC Pack is running anywhere in the environment.
  • Cross-check your organization’s exposure against Microsoft’s Security Update Guide rather than relying on any single third-party total.

What Comes Next: Five Predictions for the Rest of 2026

A few things look likely to play out over the coming weeks and months:

  • Expect scanning activity against Windows DNS Server to spike within days of the CVE-2026-62878 disclosure, following the pattern set by past wormable RCE bugs once proof-of-concept code circulates.
  • Expect vulnerability-management vendors to keep publishing divergent monthly totals, since there’s no sign of an industry-wide standard forcing a single counting method.
  • Expect developer-tooling CVEs, in products like GitHub Copilot and Visual Studio Code, to become a bigger share of future Patch Tuesdays as AI-assisted coding tools get more deeply wired into enterprise pipelines.
  • Expect enterprise buyers to keep comparing scanning platforms like Tenable Nessus, Qualys, and open-source options such as OpenVAS and Nuclei against each other, since that competitive category comparison is already active heading into the back half of 2026.
  • Expect the September 2026 Patch Tuesday to draw the same round of conflicting headline totals, for the same structural reasons, unless a major vendor changes its counting methodology.

Frequently Asked Questions

How many CVEs did Microsoft actually patch in August 2026?

It depends who’s counting. Tenable and Ivanti both report 398 Microsoft-only CVEs. Qualys reports 421 when Adobe’s same-day patches are folded in. CrowdStrike reports 415. Senserva and Computerworld report 751 when counting every CVE entry touched across Microsoft’s full product portfolio. There isn’t a single official number that all vendors converge on.

Was there an actively exploited zero-day in August’s Patch Tuesday?

Yes. BleepingComputer, Tenable, and CrowdStrike all confirm one actively exploited zero-day among a total of three zero-day vulnerabilities fixed in the release. None of the three outlets’ reviewed coverage specified the exact CVE ID for the exploited bug.

What does “technically wormable” mean for CVE-2026-62878?

The Zero Day Initiative’s description means the stack-based buffer overflow in Windows DNS Server could, in principle, support an exploit that spreads from one vulnerable server to another without user interaction. It’s not confirmation that such a worm exists today, but it flags the bug as a higher operational priority than its raw severity label alone might suggest.

Why do Tenable and Ivanti report the exact same numbers?

Both report 398 CVEs, 42 rated Critical, 355 rated Important, and 1 rated Moderate. The match suggests both vendors pulled their breakdown from the same underlying Microsoft-only CVE dataset rather than performing fully independent audits.

Which Microsoft products were affected this month?

Coverage spans Windows core components (HTTP.sys, Hyper-V, NTFS, Desktop Window Manager), Microsoft Exchange Server, SharePoint Server, Office, Azure, Microsoft Defender, Dynamics Business Central, and developer tools including Visual Studio Code and GitHub Copilot.

Is CVE-2026-59124 in Microsoft HPC Pack worth patching if it’s only rated Important?

Yes, if HPC Pack is running anywhere in the environment. TechRepublic notes it was rated Important instead of Critical specifically because HPC Pack isn’t part of a default Windows install, not because the underlying remote-code-execution flaw is minor.

How should security teams prioritize patching when vendor totals disagree?

Treat the exploited zero-day and Critical-rated bugs as the non-negotiable first wave, verify installation against Microsoft’s own Security Update Guide, and use the exact total-CVE-count debate as background context rather than the figure that drives your patch schedule.

Where can I check whether a specific KB installed successfully?

On individual machines, PowerShell’s Get-HotFix cmdlet filtered by install date gives a quick answer. Fleet-wide, WSUS, Intune, or SCCM compliance reports cross-referenced against Microsoft’s Security Update Guide remain the most reliable method.