The figure of 421 vulnerabilities in a single patching cycle sounds enormous, but compared to recent months, it actually represents a decline. Microsoft recorded roughly 200 fewer vulnerabilities than in July 2026 about 200 fewer vulnerabilities, the month when the company disclosed up to 622 flaws by its own count, more than three times the June 2026 figure. This is not random fluctuation. Windows chief Pavan Davuluri warned users in July 2026 to expect the volume of security patches to rise because AI (artificial intelligence) helps detect vulnerabilities faster than humans can, and Adobe similarly cited AI when shifting to patching twice monthly.
The gap between when a vulnerability is being exploited and when a patch arrives is what should concern us, not the number 421.
Mechanism: AI finds bugs, humans rush to patch
What deserves attention is not the spike in vulnerability numbers, but the speed at which technology companies are forced to adapt. The previous Patch Tuesday record was 1,245 CVEs for the entire year 2020 1,245 CVEs — yet in July 2026 alone, Microsoft came close to half that figure in just 30 days. As security vendors' AI tools scan source code faster, the number of discovered vulnerabilities rises, but this also means malicious actors have more targets to exploit before patches arrive — a widening time gap between when a vulnerability exists and when it gets fixed.
Lazarus moved in weeks ahead
That gap is exactly what happened with CVE-2026-68820, a use-after-free flaw in the afd.sys driver that controls Windows network communication. According to security firm Check Point, researchers documented North Korean Lazarus group exploiting this vulnerability as early as June 2026, roughly two months before Microsoft released the patch on August 11, 2026. This is not the first time afd.sys became a target: since 2022, three other zero-day vulnerabilities in this driver have been exploited in the wild, and one of them was previously believed to be linked to Lazarus.
This campaign is tied to Operation Dream Job — a familiar Lazarus tactic using fake job offers to lure victims in the defense sector into opening malicious documents. According to reports, the group also set up at least three fake websites impersonating security company Enveil and distributed a fake PDF reader named SecurityPDF to install malware.
Not the first time, and won't be the last
This is a recurring pattern. In April 2026, Microsoft had to patch another zero-day vulnerability being actively exploited in SharePoint Server, CVE-2026-32201, forcing the U.S. federal Cybersecurity and Infrastructure Security Agency (CISA) to issue patch deadlines for government agencies. By July 2026, a different SharePoint vulnerability was being exploited, prompting CISA to call on organizations to tighten their systems. Every few months, the same type of enterprise platform software from American companies becomes a gateway for state-sponsored hackers.
What should worry American businesses
For small and medium-sized American companies — including not a few businesses run by Vietnamese Americans that use Windows servers for internal systems — the lesson does not lie in the number 421, but in the lag between the moment a vulnerability is exploited and the moment a patch appears. Not every organization has an IT team that closely monitors CVE alerts each month to patch in time; for small businesses, automating Windows updates and disabling unnecessary drivers is a more practical measure than waiting for news about each specific vulnerability.
Read the original reports at the source links below.
Bảo Nguyễn
Bảo Nguyễn founded Saigon Sentinel to give the Vietnamese diaspora truly independent, in-depth community coverage at a time when misinformation moves faster than fact-checks and the language barrier makes verification harder than it should be. He sets the editorial standards and quality controls that govern the reporting, chooses the subjects, writes and edits each article, reads it against its sources before publication, audits published output, and handles corrections.