I spent Sunday night staring at two numbers. Last August, Microsoft shipped 107 patches. This August it shipped 415. That is not a busier month. That is a different job.[1][2]
The pile got four times heavier
CrowdStrike’s August 11 write-up is the one I keep sending people. One exploited zero-day. Three disclosed zero-days. Sixty-two marked Critical. Elevation of privilege is still the dominant class at 174 patches, then remote code execution at 109.[1]
The exploited one is CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock. Local, race condition, SYSTEM if they win it. Microsoft says it is already in the wild.[1]
The ones I would actually lose sleep over are the unauthenticated network RCEs: Microsoft QUIC at CVSS 9.8 (CVE-2026-62815), Windows Deployment Services TFTP at 9.8, and a stack of Windows DNS Server bugs starting at 9.8.[1] If you still have WDS or an exposed DNS role sitting on a management VLAN you stopped thinking about in 2019, this is your weekend.
I am not going to pretend I applied 415 updates by hand. I am going to pretend you have a ring: internet-facing and identity-adjacent first, then domain controllers and DNS, then the rest. If your patch process still starts with “wait for the pilot ring to finish coffee,” 415 is going to bury you.
NetScaler walked back into the room
watchTowr published the post that made the rounds on /r/netsec this weekend. Citrix patched a heap overflow in NetScaler ADC and Gateway as part of bulletin CTX696604. watchTowr walks it to pre-auth remote code execution on boxes using SAML as SP or IdP. They think it is CVE-2026-8452. They also say Citrix will not cleanly map the CVE, so treat the number as their read, not gospel.[10][13]
Affected lines they list: 14.1 before 14.1-72.61, and 13.1 before 13.1-63.18.[10]
The bug lives in signature canonicalization. An oversized SignedInfo / PrefixList gets copied into a fixed buffer in nsppe. Crash the packet engine, then keep going. They even disable the crash handlers so pitboss respawns the process instead of rebooting the box, which is how the webshell survives.[10]
Three years after CVE-2023-3519, we are back in the same room. Password complexity on the SSL VPN did not save anyone then. It will not save anyone now. If the appliance is still on the internet and still doing SAML, patch it before you argue about the CVE string.
What I am doing Monday morning
- Confirm August Patch Tuesday is actually installed on anything that speaks QUIC, DNS, or WDS. Do not trust WSUS green checkmarks. Spot-check a box.[1]
- Inventory NetScaler ADC / Gateway versions. If it is below those builds and SAML is on, that is an emergency change, not a CAB item.[10]
- After you patch the gateway, rotate the secrets that sat behind it. I know. Do it anyway.
The rest of the weekend noise was the usual: another cert-transparency hunt for forgotten internal apps, another reminder that coding agents are now an attack surface. Fine. The two things that will actually page you this week are the Microsoft pile and the Citrix door.
Sources
[1] https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026 — August 2026 Patch Tuesday CrowdStrike [2] https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2025 — August 2025 Patch Tuesday CrowdStrike [10] https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452 — watchTowr Citrix CVE-2026-8452 [13] https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604 — Citrix NetScaler bulletin CTX696604
Drafted at the Dark Pixel Tech desk.