Patch Tuesday cycleAugust 2026 Patch TuesdayComplete

Canonical Patch Tuesday catalogue

August 2026 Patch Tuesday catalogue.

Complete for the active Patch Tuesday cohort: Microsoft, Adobe and SAP. 128 operational patch records link 537 unique CVEs. No claim is made for vendors outside that cohort. Each row is one deployable update or vendor advisory with linked CVEs. BlackTree timing remains separate from CVSS and vendor severity.

128Patch recordsStable operational entries, not CVE duplicates
537Linked unique CVEsEvery CVE opens in BlackTree CVE Intelligence
14Accelerated actionsOut-of-band action
3Revised entriesCanonical history remains visible

August 2026 Patch Tuesday

Patch catalogue

Search and filters execute on the server. Each response is capped at the selected bounded page size, with a maximum of 100 compact patch rows.

Hide update groups
No groups hidden

Select every group you want removed from this view, its shared URL and its filtered exports.

Adobe
Microsoft
SAP
Several vendor and product groups can be hidden together.
Additional filtersProduct, platform, exploitation, restart, issues, date and cycle state
Reset filters
128 matching recordsPage 1 of 7
Selected PDF report0 of 20 visible records selectedSelect up to 20 approved records. Filter-hidden selections remain selected until cleared.
MicrosoftDeploy Microsoft Apps update for App InstallerMSRC-2026-08-apps-release-notes · Updated 2026-08-11
Product and releaseApp Installer1.29.280
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for App Installer.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-apps-release-notes
Platform
Apps
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.3
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure Monitor Agent Linux ExtensionMSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseAzure Monitor Agent Linux Extension1.43
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure Monitor Agent Linux Extension.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.2
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft HPC Pack 2019MSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseMicrosoft HPC Pack 20196.3.8359
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft HPC Pack 2019.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 9.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Microsoft Entra ConnectMSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseMicrosoft Entra Connect2.6.84.0
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Microsoft Entra Connect.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 7.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure CycleCloud 8.9.2MSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseAzure CycleCloud 8.9.28.9.2
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.2.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 6.5
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Azure update for Azure CycleCloud 8.9.1MSRC-2026-08-azure-release-notes · Updated 2026-08-11
Product and releaseAzure CycleCloud 8.9.18.9.1
Review linked CVEs (1) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 1 linked CVE for Azure CycleCloud 8.9.1.

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-azure-release-notes
Platform
Azure
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
Vendor-linked CVEs (1)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.1
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Browser update for Microsoft Edge (Chromium-based)MSRC-2026-08-browser-release-notes · Updated 2026-08-11
Product and releaseMicrosoft Edge (Chromium-based)151.0.4129.78
Review linked CVEs (39) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 39 linked CVEs for Microsoft Edge (Chromium-based).

Open official sourceCanonical detail record

Evidence and release

Advisory
MSRC-2026-08-browser-release-notes
Platform
Browser
Restart
no
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
  • This update uses vendor release notes or a fixed build instead of a standalone KB identity.
MicrosoftDeploy Microsoft Developer Tools security update KB5120418KB5120418 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, plus 1 more2.0.50727.8984 & 3.0.30729.8980 & 4.7.4144.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120418
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120695KB5120695 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)2.0.50727.8984 & 3.0.30729.8980
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 on Windows Server 2012 R2, Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120695
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120698KB5120698 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more2.0.50727.9070 & 3.0.30729.9068 & 4.7.4144.0
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.7.2 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120698
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120699KB5120699 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation)4.7.4144.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120699
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120700KB5120700 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation)4.7.4144.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120700
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120701KB5120701 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120701
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120702KB5120702 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for 32-bit Systems, Microsoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems, Microsoft .NET Framework 4.8 on Windows Server 2016, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120702
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120703KB5120703 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more2.0.50727.9070 & 3.0.30729.9068 & 4.8.4805.0
Review linked CVEs (4) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 4 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8 on Windows 10 Version 1809 for x64-based Systems, plus 2 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120703
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (4)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120704KB5120704 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation)4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012, Microsoft .NET Framework 4.8 on Windows Server 2012 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120704
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120705KB5120705 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation)2.0.50727.9183 & 3.0.30729.9169 & 4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022, Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120705
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120706KB5120706 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation)4.8.4805.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 4.8 on Windows Server 2012 R2, Microsoft .NET Framework 4.8 on Windows Server 2012 R2 (Server Core installation).

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120706
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120708KB5120708 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, plus 1 more2.0.50727.9183 & 3.0.30729.9169 & 4.8.9344.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 11 Version 25H2 for x64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025, plus 1 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120708
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0
MicrosoftDeploy Microsoft Developer Tools security update KB5120709KB5120709 · Updated 2026-08-11
Product and releaseMicrosoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more2.0.50727.9183 & 3.0.30729.9169 & 4.8.9343.0
Review linked CVEs (3) No confirmed exploitation stated

Operational summary

This official Microsoft Patch Tuesday update addresses 3 linked CVEs for Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for 32-bit Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for ARM64-based Systems, Microsoft .NET Framework 3.5 AND 4.8.1 on Windows 10 Version 21H2 for x64-based Systems, plus 3 more.

Open official sourceCanonical detail record

Evidence and release

Advisory
KB5120709
Platform
Developer Tools
Restart
varies by product
CVE state
Complete For Update

Why this urgency

  • Fix Available
  • Routine Review

Vendor signal: Important

Decision confidence: high

Known gaps and caveats

  • Confirm exact product, edition and architecture applicability in the Microsoft Security Update Guide before deployment.
Vendor-linked CVEs (3)0 confirmed exploited · 0 with PoC or lab evidence · max CVSS 8.8
Confirmed exploitedCVSS above 9.0