BlackTreeBlackTreeCVE Intelligence
Patch Tuesday catalogueVerified vendor sources

Patch Intelligence

Every Patch Tuesday update, grouped for action.

Use the compact catalogue to see each deployable update or vendor advisory, its linked CVEs, and whether BlackTree recommends the normal patch window or faster action. CVSS and vendor severity remain source signals, not the BlackTree action window.

128Current-cycle patchesOperational updates, not CVE duplicates
537Linked unique CVEsRelationships can appear in several applicable patches
14Accelerated actionsIncludes out-of-band and 72-hour recommendations
3 of 9Active vendor sourcesSources that can publish after all checks pass

Vendor visibility

Published and monitored vendor sources

The four main vendors are shown here. Open the full vendor list below to show or hide the other registered vendors. A checked vendor can only display records that have passed publication review.

Official monthly MSRC CVRF, filtered to Patch Tuesday revisions and grouped by deployable vendor fix.

Last check
26 Aug 2026, 11:55 UTC
Verified records
92
Event gate
active cohort
Official vendor overview
92 verifiedSource details

Official monthly MSRC CVRF, filtered to Patch Tuesday revisions and grouped by deployable vendor fix.

Last check
26 Aug 2026, 11:55 UTC
Verified records
92
Event gate
active cohort
Official vendor overview

Official bulletin index filtered to the Patch Tuesday date, with every same-day bulletin validated.

Last check
26 Aug 2026, 11:55 UTC
Verified records
5
Event gate
active cohort
Official vendor overview
5 verifiedSource details

Official bulletin index filtered to the Patch Tuesday date, with every same-day bulletin validated.

Last check
26 Aug 2026, 11:55 UTC
Verified records
5
Event gate
active cohort
Official vendor overview

Official scheduled SAP Security Patch Day table, including stated same-day revisions.

Last check
26 Aug 2026, 11:55 UTC
Verified records
31
Event gate
active cohort
Official vendor overview
31 verifiedSource details

Official scheduled SAP Security Patch Day table, including stated same-day revisions.

Last check
26 Aug 2026, 11:55 UTC
Verified records
31
Event gate
active cohort
Official vendor overview

Official Apple security releases are monitored. Only a release proven to belong to this exact Patch Tuesday event can add public rows.

Last check
26 Aug 2026, 11:57 UTC
Verified records
0
Event gate
Exact-event evidence required
Official vendor overview
0 verifiedSource details

Official Apple security releases are monitored. Only a release proven to belong to this exact Patch Tuesday event can add public rows.

Last check
26 Aug 2026, 11:57 UTC
Verified records
0
Event gate
Exact-event evidence required
Official vendor overview
9 of 9 vendor controls selected
Show or hide the full 9-vendor list

Every registered source below is checked automatically. The status describes what the collected evidence is allowed to do. Complete sources passed the cycle completeness gate. Monitored sources are checked automatically but are not assumed to belong to Microsoft Patch Tuesday. Private validation sources can identify exact-date candidates, while completeness is still being measured. None of the latter two states can create public rows. Checked vendors will appear automatically if they later gain approved Patch Tuesday records. A registered source is included only when an official advisory is demonstrably part of the coordinated Patch Tuesday event. Rolling and ordinary monthly releases remain excluded.

Microsoft
Monthly plus out-of-cycle · Active Exact DateOfficial overview
Adobe
Rolling · Exact Date BulletinsOfficial overview
SAP
Monthly plus revisions · Named Security Patch DayOfficial overview
Apple
Rolling · Exact Event Evidence RequiredOfficial overview
Rolling · Exact Event Evidence RequiredOfficial overview
Rolling · Exact Event Evidence RequiredOfficial overview
Rolling · Exact Event Evidence RequiredOfficial overview
Second Tuesday plus critical out-of-cycle · Private Automation ValidationOfficial overview
Second Tuesday plus out-of-cycle · Private Automation ValidationOfficial overview

Patch catalogue

Operational Patch Tuesday records

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
128 matching recordsPage 1 of 7
Selected PDF report0 of 20 records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
MicrosoftDeploy Microsoft Apps update for App InstallerMSRC-2026-08-apps-release-notes · Updated 2026-08-11
Product and releaseApp Installer1.29.280
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for App Installer.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.3
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Monitor Agent Linux ExtensionMSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseAzure Monitor Agent Linux Extension1.43
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent Linux Extension.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.2
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft HPC Pack 2019MSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseMicrosoft HPC Pack 20196.3.8359
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft Entra ConnectMSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseMicrosoft Entra Connect2.6.84.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Entra Connect.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure CycleCloud 8.9.2MSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseAzure CycleCloud 8.9.28.9.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.2.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure CycleCloud 8.9.1MSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseAzure CycleCloud 8.9.18.9.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.1.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Browser update for Microsoft Edge (Chromium-based)MSRC-2026-08-browser-release-notes · Updated 2026-08-11
Product and releaseMicrosoft Edge (Chromium-based)151.0.4129.78
Review linked CVEs (39) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 39 linked CVEs for Microsoft Edge (Chromium-based).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-browser-release-notes
Platform
Browser
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5120418KB5120418 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, plus 1 more2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120418
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120695KB5120695 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)2.0.50727.8984 & 3.0.30729.8980
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120695
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120698KB5120698 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120698
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120699KB5120699 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)4.7.4144.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120699
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120700KB5120700 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)4.7.4144.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120700
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120701KB5120701 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120701
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120702KB5120702 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120702
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120703KB5120703 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120703
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120704KB5120704 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120704
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120705KB5120705 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120705
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120706KB5120706 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120706
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120708KB5120708 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, plus 1 more2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120708
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120709KB5120709 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120709
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0

Evidence first

You can see where each fact came from

Official facts stay separate

Vendor statements, CVE descriptions, confirmed exploitation and probability estimates answer different questions. BlackTree keeps them separate and records when each source was checked. This prevents an estimate or a third-party description from being presented as if the vendor confirmed it.

Operational urgency

A severe issue does not always require an emergency patch

The action window is explained

CVSS describes possible technical impact. It does not tell you whether attackers are using the issue, whether your systems are exposed, or whether a safe fix exists. BlackTree considers those practical signals separately and explains why an update belongs in the normal maintenance window, within 72 hours, or in an immediate patch window.

Publication checks

Incomplete information stays private

Public rows must pass every check

A new update first enters a private review area. It is published only after the official source, release date, affected products, fixed versions and linked CVEs have been checked and the source run is complete. Conflicting, missing or uncertain information stays out of the public catalogue until it is resolved.