Microsoft August Patch Tuesday fixes 400+ flaws including 3 zero-days

August's patch cycle is unusually large at roughly 400 CVEs, underscoring the expanding attack surface as AI tooling gets woven into Microsoft's stack. Of these, 42 are rated critical and 37 are remote-code-execution flaws — the most dangerous class, allowing attackers to run code on target systems. Three were zero-days, meaning they were known or exploited before a patch existed, and at least one was under active exploitation.
Notably, the fixes span AI-adjacent products including GitHub Copilot and Visual Studio Code, alongside core infrastructure like Hyper-V and Exchange. The inclusion of Copilot in a security bulletin reflects how AI coding assistants are now part of the enterprise threat model — a theme echoing the week's broader agentic-security anxieties.
The cycle followed an emergency out-of-band update on August 6 addressing CVSS 10.0 (maximum severity) flaws in Microsoft Teams and Entra, indicating the month's threat activity was severe enough to warrant patching outside the normal cadence.
For enterprises, the volume and severity make rapid patching essential, particularly for the actively-exploited zero-day. Security analysts from Qualys and others flagged the RCE-heavy composition as the key risk. What to watch: exploitation trends for the patched zero-days and whether the Copilot and VS Code fixes prompt scrutiny of AI-tool supply-chain security. The scale itself is a reminder that AI-era productivity gains come with a widening security burden.