Windows & Microsoft AI News: Game Crash & KEV (Aug 21)

- • Game crash probe: Microsoft confirmed on August 19 that it is investigating game crashes linked to KB5121003 (builds 26100.9168 and 26200.9168); removing the inpoutx64.sys driver restores affected games (Gigazine, Aug 21, 2026).
- • SharePoint KEV: CISA added CVE-2026-55040 (CVSS 9.1, on-prem SharePoint weak authentication) to its exploited catalog on August 18, with a federal remediation deadline of August 21 (The Hacker News, Aug 19, 2026).
- • Ransomware escalation: CISA confirms ransomware groups are exploiting CVE-2025-60710, a Task Host privilege-escalation bug patched since November 2025 (ThaiCERT, Aug 20, 2026).
- • Copilot multitasking: Outlook for Mac and iPad starts rolling out a default-on floating Copilot Chat window in late August; no admin action is needed (MWPro, Aug 20, 2026).
- • Privacy parity: Windows 11 Insider build 26340.9212 adds per-app camera, microphone, location, and voice-activation controls to Win32 apps for the first time (Ghacks, Aug 20, 2026).
01Game Crashes Linked to August 11 Update
Microsoft confirmed on August 19 that it is investigating reports of game crashes linked to the August 11 Windows 11 update, KB5121003. Gigazine reported on August 21 that the update takes Windows 11 24H2 to build 26100.9168 and Windows 11 25H2 to build 26200.9168. Affected titles include ARC Raiders, The Finals, and MARVEL Tokon: Fighting Souls, with symptoms ranging from games freezing or closing without an error to EXCEPTION_ACCESS_VIOLATION faults and, in some cases, a black screen followed by a system restart.

Embark Studios, the developer of ARC Raiders and The Finals, traced the issue to a loss of compatibility with the inpoutx64.sys kernel driver, and removing that driver restores normal behavior. The driver is a low-level I/O access helper used by some gaming and hardware tools, which is why the failure hits specific titles and configurations rather than every updated PC. The same update cycle had already drawn attention for its Low Latency Profile work in game-related settings.
For gamers, the practical guidance is to keep the August update, test affected titles, and remove or update the inpoutx64.sys driver if games crash; Microsoft’s investigation is still open, so a formal fix may follow. For IT teams, the incident is a reminder that monthly updates can carry app-compatibility regressions, and that a short verification window after Patch Tuesday is worth building into every rollout plan.
02SharePoint CVE-2026-55040 Added to KEV
CISA added CVE-2026-55040, a critical authentication flaw in on-premises SharePoint Server, to its Known Exploited Vulnerabilities catalog on August 18. The Hacker News reported on August 19 that the flaw, rated 9.1 out of 10, follows a published proof of concept and is now being exploited by unknown actors. The weakness is classified as CWE-1390, improper authentication, and it can be triggered remotely without authentication, according to CISA’s alert as summarized by CSIRT Telconet.

The affected products are on-premises SharePoint Server Subscription Edition, 2019, and 2016; SharePoint Online is not vulnerable, so organizations that only use cloud SharePoint have no action. CISA’s Binding Operational Directive sets a remediation deadline of August 21, 2026 for US federal agencies, which makes this a patch-now item for the rest of the industry as well.
Separately, researchers disclosed on August 11 an AI-assisted chain that combines a JWT authentication bypass with CVE-2026-63520, a Business Connectivity Services remote code execution flaw, letting an attacker reach an authenticated on-premises SharePoint server. Rapid7 discovered the chain with AI assistance, and the July update already fixed both pieces. The two disclosures reinforce the same conclusion: on-premises SharePoint is an increasingly attractive target, and unpatched servers are the weak link.
03Task Host Flaw Exploited by Ransomware
CISA confirmed that ransomware groups are now exploiting CVE-2025-60710, a privilege-escalation flaw in the Host Process for Windows Tasks. ThaiCERT summarized the warning on August 20, 2026: the vulnerability lets a standard user elevate to SYSTEM on unpatched Windows 11 and Windows Server 2025 systems. Microsoft fixed the bug in its November 2025 security updates, and CISA added it to its exploited-vulnerabilities catalog in April 2026; the new confirmation is that real ransomware operations are actively using it in attacks.
The pattern matters because this is not a zero-day: the patch has existed for months, yet unpatched machines remain in production. Ransomware groups favor exactly this kind of reliable local escalation, pairing it with initial access obtained through phishing, stolen credentials, or exposed remote services.
For IT teams, the action is to verify that the November 2025 update or later is present on every Windows 11 and Windows Server 2025 host, and to check CISA’s catalog for other flaws in the same wave. If fleet management cannot prove the patch is installed, treat those hosts as exposed until they are updated.
04Outlook Copilot Chat Gets a Floating Window
Outlook for Mac and iPad is rolling out a floating Copilot Chat window that can be popped out from the main app for easier multitasking. Microsoft 365 message center post MC1454996, updated August 19, 2026, describes the feature as a pop-out, independent window that is enabled by default. The rollout starts in late August 2026 and is expected to complete by mid-September.

On Mac, the window can be dragged and resized inside the Outlook window; on iPad, it can be moved horizontally and resized vertically. Users can return Copilot to the main window with a Return button or close the floating window entirely with a Close button.
There is no admin action required, which makes this a low-touch change for IT teams. For users, the practical benefit is keeping a chat open while composing, reading, or managing calendar items, and the feature should simply appear as the rollout reaches each tenant.
05Per-App Privacy Controls Reach Win32 Apps
A new Windows 11 Insider build gives Win32 desktop programs per-app camera, microphone, location, and voice-activation controls for the first time. Ghacks reported on August 20, 2026 that build 26340.9212, released as an Experimental build on August 17 and spotted by Windows enthusiast @jakub25050 on August 18, extends privacy toggles that were previously exclusive to Microsoft Store apps. The same build also removes the legacy WMIC command-line tool.
The change matters because classic Win32 applications are the ones that most often bypass the app-level privacy model; users could previously deny them only at the device level. Per-app toggles give the same granular audit and control to legacy software without uninstalling it.
Microsoft has not announced a formal rollout plan for the feature, and Experimental builds are for testing only, so treat this as a preview of direction rather than a release date. Privacy teams can begin planning policy and user communication now, so they are ready when the controls reach stable Windows 11.
06Azure Copilot Adds Direct Agent Access
Azure Copilot now offers direct access to specialized agents that handle specific cloud operations, starting this month. A summary of Microsoft’s announcement, published in August 2026, lists six agents: Deployment, Troubleshooting, Optimization, Resiliency, Observability, and Migration. Instead of describing a problem and waiting for a general answer, users can pick the agent built for the task.
The agent picker is the main interface change, with the Azure Copilot documentation updated around August 10, 2026. For example, the Troubleshooting agent can shorten the path from symptom to root cause, while the Migration agent focuses on the workflow of moving workloads.
For Azure teams, the value is faster, more focused assistance inside the console, and the agents are worth testing in non-production subscriptions first. Because the feature is still rolling out, verify what is available in your region before building workflow expectations around it.
07What This Means for Windows Users and IT Teams
The week’s Windows and Microsoft AI news condenses into three actions: patch the exploited SharePoint and Task Host flaws, watch the KB5121003 game-crash investigation, and explore the new Copilot surfaces as they roll out. Security work leads the list because two of the week’s flaws are already in CISA’s exploited catalog, and one of them is confirmed to be used by ransomware groups.
For Windows users: if games crash after the August 11 update, remove or update the inpoutx64.sys driver while Microsoft investigates; keep Windows Update current, because the SharePoint and Task Host patches are already available; and expect the Outlook Copilot floating window to appear by mid-September.
For IT teams: verify the SharePoint Server patch for CVE-2026-55040 and the November 2025 Task Host fix on every affected host, use the CISA KEV list as a compliance checklist, and test the Azure Copilot agents in non-production. For licensing decisions that intersect with these changes, the Best Windows License Buying Guide 2026, the Windows 11 Pro vs Home guide, and the Windows 10 vs Windows 11 comparison cover the common paths.
The through-line is defense in depth: patch quickly, verify every layer of protection is honestly healthy, and treat update investigations as security work. Teams that confirm patch status this week for SharePoint and Task Host will be in a far better position than those that wait.
FAQ
Is the game-crash bug affecting every Windows 11 PC?
No. It affects PCs on the August 11 update (builds 26100.9168 for 24H2 and 26200.9168 for 25H2) running titles such as ARC Raiders, The Finals, and MARVEL Tokon: Fighting Souls. Removing the inpoutx64.sys driver restores normal behavior, and Microsoft confirmed an investigation on August 19, 2026 (Gigazine, Aug 21, 2026).
Does the SharePoint KEV apply to SharePoint Online?
No. CVE-2026-55040 affects on-premises SharePoint Server Subscription Edition, 2019, and 2016 only; SharePoint Online is not vulnerable (The Hacker News, Aug 19, 2026).
Is the Windows Task Host vulnerability already patched?
Yes. Microsoft fixed CVE-2025-60710 in its November 2025 security updates. CISA now confirms ransomware groups are exploiting unpatched Windows 11 and Windows Server 2025 systems, so verify the patch is installed (ThaiCERT, Aug 20, 2026).
Do I need to configure anything for the Outlook Copilot floating window?
No. The feature is enabled by default, and no admin action is required. The rollout runs from late August to mid-September 2026 (MWPro / MC1454996, Aug 20, 2026).
When will per-app privacy controls reach stable Windows?
Microsoft has not announced a timeline. The controls currently exist in Experimental build 26340.9212, so treat them as a preview of direction rather than a release date (Ghacks, Aug 20, 2026).
External References
- • Gigazine: Windows 11 update breaks games; Microsoft confirms investigation (Aug 21, 2026)
- • IT之家 via 163: KB5121003 game crash reports, builds 26100.9168 / 26200.9168 (Aug 20, 2026)
- • The Hacker News: CISA adds critical macOS, SharePoint, vCenter, and IKE flaws to KEV (Aug 19, 2026)
- • CSIRT Telconet: CISA alert on actively exploited critical SharePoint authentication flaw (Aug 18, 2026)
- • The Hacker News: Researchers disclose AI-assisted SharePoint Server exploit chain (Aug 11, 2026)
- • ThaiCERT: CISA warns Windows Task Host vulnerability exploited by ransomware groups (Aug 20, 2026)
- • MWPro: MC1454996 Outlook for Mac and iPad gets floating Copilot Chat window (Aug 20, 2026)
- • Ghacks: Windows 11 test build adds per-app privacy controls for desktop programs (Aug 20, 2026)
- • Microsoft Learn: Windows Insider Experimental build 26340.9212 release notes (Aug 17, 2026)
- • Gixtools: Azure Copilot introduces direct access to agents (Aug 2026)
- • WindowsForum: Azure Copilot picker adds agents; Observability is billed (Aug 19, 2026)
This article was compiled with AI assistance for research and drafting and has been editorially reviewed. All sources are listed above.