KB5120994: what it fixes and who gets it
KB5120994 is a security hotpatch update from Microsoft's August 2026 release for Windows 11 Version 24H2, Windows 11 Version 25H2.
Microsoft data read
Should you install it?
Yes, and soon: it closes a hole that was already being used in real attacks before the fix was released. Windows Update installs it automatically on supported home PCs.
If the installation fails or the PC misbehaves afterwards, note the exact error code first: the fix depends on it. Our update troubleshooting guides are linked on this page.
Security fixes in KB5120994
| CVE | Type | CVSS | Severity |
|---|---|---|---|
| CVE-2026-68820Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Elevation of Privilege | 7.0 | ExploitedImportant |
| CVE-2026-62815Microsoft QUIC Remote Code Execution Vulnerability | Remote Code Execution | 9.8 | Critical |
| CVE-2026-62816Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-62822Windows GDI+ Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Critical |
| CVE-2026-62819Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Critical |
| CVE-2026-62889Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Critical |
| CVE-2026-62890Windows GDI+ Elevation of Privilege Vulnerability | Remote Code Execution | 7.8 | Critical |
| CVE-2026-66799Windows Key Guard Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Critical |
| CVE-2026-49179Windows Active Directory Domain Services Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-62784Microsoft Local Security Authority Server (lsasrv) Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-62785Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-62790Windows SMBv3 Server Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-62795Windows LDAP - Lightweight Directory Access Protocol Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-62800Windows SMBv3 Server Remote Code Execution Vulnerability | Remote Code Execution | 8.8 | Important |
| CVE-2026-62781RPC Runtime Library Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important |
| CVE-2026-62792Windows TCP/IP Remote Code Execution Vulnerability | Remote Code Execution | 8.1 | Important |
| CVE-2026-6726MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse | Spoofing | 7.9 | Important |
| CVE-2026-42976Remote Access Management service/API (RPC server) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-54984Windows Imaging Component Remote Code Execution Vulnerability | Remote Code Execution | 7.8 | Important |
| CVE-2026-59127Windows Installer Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61349Windows Work Folder Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61353Windows Telephony Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61355Windows Sensor Data Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61356Windows Remote Desktop Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61357Application Information Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61358Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61359Windows Storage Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61364Windows Remote Desktop Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61365Windows Remote Desktop Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61367Windows Remote Desktop Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61923Windows Display Enhancement Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61925Windows Installer Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61926Windows USB Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61930Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61934Windows Bind Filter Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-61937Windows HTTP.sys Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62688Windows MIDI Service Module Elevation of Privileges Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62692Windows Remote Desktop Services Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62695Windows Storage Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62696Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62698Microsoft Digest Authentication Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62700Windows NTFS Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62701Windows Telephony Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62707Windows Modern Device Management (MDM) Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62710Windows Device Association Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62711Windows Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62712Windows Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62713Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62717Windows Message Queuing Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62719Windows Message Queuing Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62722Microsoft Brokering File System Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62732Windows Telephony Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62733Windows Win32k Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62735Windows HTTP.sys Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62736Windows DHCP Client Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62737Windows Kernel Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62739Windows HTTP.sys Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62741Windows HTTP.sys Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62747Windows Device Association Service Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
| CVE-2026-62751Windows Projected File System Elevation of Privilege Vulnerability | Elevation of Privilege | 7.8 | Important |
Showing the 60 most severe of 194. The full list is in Microsoft's Security Update Guide.
Questions and experiences
Ask about this page: members and our editors answer. Reading is open; writing needs a free account.
0 comments
…