
Microsoft released its monthly security update on 11 August 2026, and one of the flaws it fixed was already being used by attackers before the patch existed. If your business runs Windows and you haven't installed this month's updates yet, that's the job to move up your list. Here's what actually matters and what to check.
What happened
Every second Tuesday of the month (Australian Wednesday, because of the time difference), Microsoft ships its scheduled batch of security fixes, known in the industry as Patch Tuesday. This month's release covered roughly 400 vulnerabilities across Windows, Office, Azure and related products, with dozens rated Critical.
Two things in this batch stand out for ordinary businesses, not just large enterprises:
An already-exploited Windows flaw. A vulnerability in a core piece of Windows networking (the Ancillary Function Driver for WinSock, which handles network connections at a low level) let an attacker who already had some access to a machine escalate themselves to full SYSTEM privileges, the highest level of control on that computer. Security researchers say it had already been used in real attacks before Microsoft's fix shipped, which is what makes it a genuine "patch now" item rather than routine maintenance.
A critical SharePoint Server flaw. A separate, high-severity bug in on-premises SharePoint Server could let an attacker run code over the network with very little effort. This one only affects businesses running their own SharePoint server on-site, not the SharePoint that comes with a standard Microsoft 365 subscription, but for the businesses it does affect, it's a priority.
Neither of these needs a sophisticated attacker to be dangerous. Once a fix is public, the technical details of the flaw usually become public too, and automated tools start scanning the internet for machines that haven't been patched within days.
Why this matters more than it might sound like
A lot of Perth businesses treat Windows updates as a background nuisance, something that pops up, asks to restart the computer, and gets put off "until tonight." Most months, that's a low-risk habit. This month, it's the difference between a routine patch and a machine an attacker could already be probing.
The pattern with an actively-exploited flaw like this one is predictable: attackers who already have a foothold on a network (through a phishing email, a stolen password, or a vulnerable internet-facing service) use flaws like this one to jump from "one compromised laptop" to "administrator of the whole system." It's rarely the first step in an attack. It's the step that turns a minor incident into a serious one, which is exactly why it's worth closing quickly.
What to check this week
Confirm Windows Update has actually run. Go to Settings > Windows Update on a few machines and check the last update was installed in the last few days, not weeks ago. A "restart pending" notification that's been dismissed repeatedly means the fix isn't actually applied yet.
Don't let servers slip. Workstations often update themselves reasonably well through default settings; servers and specialised machines are more often on manual or delayed update schedules, and are exactly the systems attackers value most.
If you run SharePoint Server on-site, prioritise that patch specifically and check with whoever manages it that it's been applied, since this flaw is remotely exploitable.
If a device can't be restarted for a few days, that's a real business trade-off, not a reason to skip the patch indefinitely. Schedule the restart for the soonest quiet window rather than letting it drift.
None of this requires special tools, just making sure updates that are supposed to be automatic actually are.
The bigger habit this points to
Reactively patching after reading a headline is better than nothing, but it's not a strategy. Patching within a defined, short window of a fix being released is one of the core controls in the ASD Essential Eight, the cybersecurity framework the Australian government recommends for businesses of every size, and it's one of the cheapest, highest-value things a business can get right. If you want the practical detail on the tools that make consistent patching realistic without someone manually checking every machine, see our guide on building an Essential Eight stack.
It sits alongside the other basics we talk about constantly because they genuinely stop most incidents before they start: multi-factor authentication on every account, tested backups, and layered email security. A monthly Windows update that gets applied within a few days closes the door before most attackers even try the handle.
Get ahead of it
If you're managing patching yourself across a handful of machines and a server, this is a reasonable month to double-check everything actually updated. If you're not sure whether your current setup patches consistently, or you'd rather this was simply handled in the background every month without you needing to track Patch Tuesday releases, that's exactly what managed IT support is for, monitoring, patching and securing your systems proactively so a headline like this one is a non-event rather than a scramble. Get in touch or call (08) 9325 1196. We've kept Perth businesses patched and protected since 1997.



