Live Windows Security Brief for August 4, 2026: Microsoft Updates and Identity Risk

Live Windows Security Brief for August 4, 2026: Microsoft Updates and Identity Risk

Live Windows and Microsoft security coverage for Patch Tuesday, identity systems, SharePoint, Exchange, endpoints, servers, and privilege exposure.

Microsoft estate view

Microsoft remediation should connect the Security Update Guide and active-exploitation signals to the specific products and builds deployed across endpoints, servers, identity platforms, and collaboration infrastructure.

For August 4, 2026, the lead development is CVE-2026-62870: Use after free in Microsoft Office Excel allows an unauthorized attacker to…. The remaining items below add the product-specific context needed to turn the headline into an owned security decision.

Windows and identity developments

CVE-2026-62870: Use after free in Microsoft Office Excel allows an unauthorized attacker to…

NIST National Vulnerability Database | August 4, 2026 | HIGH | CVSS 8.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

Why it matters: CVE-2026-62870 may control a traffic or administration path that other systems implicitly trust, making reachability and management-plane exposure more important than the headline score alone.

What to verify: Inventory affected models and firmware, close public administration paths, compare routes and configuration, inspect flow and DNS logs, and validate connectivity after the upgrade.

Operational focus: Check supported builds, update installation, restart state, and the current running version.

Open the original NIST National Vulnerability Database record

CVE-2026-57092: Windows VMSwitch use-after-free privilege escalation

NIST NVD and Microsoft | July 15, 2026 | CRITICAL | CVSS 9.9 | Microsoft Windows VMSwitch

Microsoft describes a network-reachable VMSwitch use-after-free that lets an authorized attacker elevate privileges. The Microsoft CNA rates it 9.9 Critical.

Why it matters: Microsoft Windows VMSwitch is likely connected to identity, collaboration, or privileged Windows workloads, where one exposed role can widen impact beyond a single endpoint.

What to verify: Map supported builds and server roles, prioritize public and identity systems, confirm the installed update plus restart state, and review authentication and EDR telemetry for abnormal activity.

Operational focus: Prioritize domain, federation, collaboration, and internet-facing servers before normal endpoint queues.

Open the original NIST NVD and Microsoft record

CVE-2026-66318: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to…

NIST National Vulnerability Database | August 4, 2026 | HIGH | CVSS 8.1

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Why it matters: CVE-2026-66318 may control a traffic or administration path that other systems implicitly trust, making reachability and management-plane exposure more important than the headline score alone.

What to verify: Inventory affected models and firmware, close public administration paths, compare routes and configuration, inspect flow and DNS logs, and validate connectivity after the upgrade.

Operational focus: Review privileged access and endpoint telemetry for signs of abuse before and after patching.

Open the original NIST National Vulnerability Database record

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Microsoft Security Blog | August 1, 2026

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first…

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus