Unsubscribe
Welcome to the August 2026 edition of Patch Monday.
This month’s patch cycle includes security updates from Adobe, Google Chrome, Mozilla, and Zoom. While most vendors delivered a relatively routine set of updates, Adobe Campaign Classic and Google Chrome deserve particular attention this month.
Here’s what you need to know.
Adobe Campaign Classic: Patch This One Now
Let’s start with the update that should be at the top of your patching queue. Adobe released security updates for several products this month, but Adobe Campaign Classic stands out. The vulnerability affects both Windows and Linux platforms and applies specifically to full on-premises deployments. Adobe-hosted instances have already been remediated. There are several reasons this deserves immediate attention.
Priority 1 | CVSS 10.0 | Arbitrary Code Execution
The update addresses three CVEs associated with arbitrary code execution vulnerabilities and Adobe has assigned the bulletin its highest Priority 1 rating. Adobe recommends deploying the update within 72 hours. A CVSS score of 10.0 is as serious as it gets. Combine that with arbitrary code execution and a Priority 1 vendor rating, and this is not a vulnerability you want lingering in your backlog. If you have an affected on-premises Adobe Campaign Classic deployment, patch it as soon as possible.
Chrome: 766 Vulnerabilities and Counting
Google Chrome had another exceptionally busy month. In the past 30 days alone, Chrome has addressed 766 vulnerabilities, making this the largest Chrome patch volume we've seen so far this year. Chrome also received six separate version updates during that period, addressing 26 Critical-rated vulnerabilities. There is one important piece of good news: none of the vulnerabilities were known zero-days at the time the respective updates were released. That doesn't mean you should wait. The combination of 766 vulnerabilities, 26 Critical-rated issues, and six separate browser update releases makes Chrome a significant patch-management priority this month. Browsers are particularly attractive targets because they sit directly on the endpoint attack surface and routinely process untrusted content. Make sure Chrome is fully patched across your environment. The latest version is listed in the chart below.
Mozilla & Zoom: Business as Usual For Mozilla and Zoom
August was a relatively normal patch cycle. Both vendors released their expected security updates, but there were no major developments that require additional attention beyond your normal patch-management process.
3rd Party Patch Priorities for August
If you're trying to prioritize your August patch workload, I'd put these two at the top:
1. Adobe Campaign Classic — CRITICAL Priority 1, CVSS 10.0, and multiple arbitrary code execution vulnerabilities. Patch immediately if affected.
2. Google Chrome — HIGH PRIORITY with 766 vulnerabilities addressed in 30 days, including 26 Critical-rated vulnerabilities. Get endpoints updated.
3. The remaining Mozilla and Zoom updates should be incorporated into your normal monthly patch cycle.
As always, review the complete table below for affected products, versions, CVEs, severity ratings, and recommended updates.
Stay secure, stay patched, and happy patching!
So, without further ado, here’s the chart of non-Microsoft 3rd party patches that affect Windows platforms in the past month.
Thanks as always for reading and best wishes on security,
Randy Franklin Smith
Click here to unsubscribeUltimate Windows Security is a division of Monterey Technology Group, Inc. ©2006-2026 Monterey Technology Group, All rights reserved. You may forward this email in its entirety but all other rights reserved.
1162 Manus Chapel Road, Mill Springs, NC 28756
Note: We do our best to provide quality information and expert commentary but use all information at your own risk.