UpdateStar Vulnerability Index · August 2026
Monthly severity snapshot for widely-installed consumer software
SEVERE
August 2026 saw Microsoft ship its second-largest Patch Tuesday of the year — roughly 421 CVEs — including a fix for a Windows kernel-driver zero-day (AFD.sys) that North Korea's Lazarus group had been exploiting since early July in attacks on defense and aerospace targets. WinRAR's 2025 path-traversal flaw is now in its 13th month of active nation-state abuse. Chrome and Firefox both shipped large batches of critical and high-severity fixes with no confirmed in-the-wild attacks — but a low-severity 7-Zip Mark-of-the-Web bypass remains unpatched with no fix available at all.
Top 5 — Consumer App Severity
CVE-2026-68820
CVE-2025-8088
CVE-2026-76034 / -76036
CVE-2026-58052
MFSA 2026-74
CVSS Score Comparison
Key Stats — August 2026
Patch Lag — Days Since Disclosure vs. Update Status
Check and update all software at updatestar.com · Download the UpdateStar Client for Windows
August 2026 Highlights
- KEV2 CVEs on CISA Known Exploited Vulnerabilities list (1 new — Windows AFD.sys, 1 carryover — WinRAR)
- APTLazarus exploiting a fresh Windows kernel zero-day; RomCom, Turla, Gamaredon and a PRC-linked actor continue abusing WinRAR
- FIX7-Zip's Mark-of-the-Web bypass has no fix available even in the latest release
- MS~421 Microsoft CVEs in a single Patch Tuesday — the 2nd-largest batch of 2026
Overall Severity Score
App Quick Reference
-
HIGH WinRAR
8.4 -
HIGH Windows (AFD.sys)
7.0 -
CRIT Chrome
Critical* -
HIGH Firefox
High* -
MED 7-Zip
4.8
Patch Status
- Windows — patched Aug 11 (KB5121003/KB5120249); KEV-listed
- WinRAR — patched but no auto-update, still actively exploited
- Chrome — patched (151.0.7922.169/.170); no confirmed ITW
- 7-Zip — not yet patched, no auto-update
- Firefox — patched (154, auto-update); no confirmed ITW
Data Sources
- NVD (National Vulnerability Database)
- CISA Known Exploited Vulnerabilities
- Mandiant M-Trends 2026
- Verizon DBIR 2026
- Vendor security advisories