Microsoft released its monthly Patch Tuesday security update on Tuesday, fixing dozens of vulnerabilities across Windows, Office and Azure, including flaws the company said were being actively exploited. The update was pushed to Windows systems worldwide.
Patch Tuesday falls on the second Tuesday of each month, and August 11 marked the scheduled release. Microsoft's Security Response Center published its advisory detailing affected products, severity ratings and recommended actions for system administrators.
The update included patches rated critical by Microsoft, several addressing remote code execution risks in core Windows components. The company typically flags vulnerabilities as being exploited in the wild or publicly disclosed, prompting security teams to prioritise those fixes.
Enterprise administrators and managed service providers were expected to test and deploy the patches quickly, following guidance from Microsoft and the US Cybersecurity and Infrastructure Security Agency, which routinely urges organisations to apply fixes without delay. Adobe and other vendors including Google also commonly issue coordinated security updates on the same day.
Microsoft has used the monthly cycle for more than two decades to consolidate security fixes, giving IT departments a predictable schedule. The August release continued a year in which the company has repeatedly patched vulnerabilities affecting Windows and its cloud services as ransomware and state-linked intrusion campaigns have intensified.