Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities including 62 rated critical. One vulnerability, CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0), has been exploited in the wild as a local elevation of privilege flaw. Critical RCE vulnerabilities span Windows server components (DNS, DHCP, TFTP, AD CS, RRAS, SSTP, iSCSI), desktop applications (Office, Excel, SharePoint, Remote Desktop Client), and cloud services (Azure SQL, Azure Service Bus, Azure AD, Microsoft Teams). Talos released Snort rules providing network-level detection for exploitation attempts against a subset of these vulnerabilities.
- cveCVE-2026-50481Modification of assumed-immutable data allowing an authorized attacker to elevate privileges over a network (CVSS 9.9).
- cveCVE-2026-50515Deserialization of untrusted data allowing an authorized attacker to execute code over a network (CVSS 9.9).
- cveCVE-2026-50516Missing authentication for critical function allowing an unauthorized attacker to elevate privileges over a network (CVSS 9.4).
- cveCVE-2026-56161Improper access control allowing an authorized attacker to disclose information over a network (CVSS 9.6).
- cveCVE-2026-56162Improper authentication allowing an unauthorized attacker to elevate privileges over a network (CVSS 10.0).
- cveCVE-2026-59115Path traversal allowing an authorized attacker to elevate privileges over a network (CVSS 9.9).
- cveCVE-2026-59118Improper authorization allowing an unauthorized attacker to elevate privileges over a network (CVSS 9.3).
- cveCVE-2026-62815Use-after-free allowing an unauthorized attacker to execute code over a network (CVSS 9.8).
- cveCVE-2026-62818Use-after-free allowing an authorized attacker to execute code over a network (CVSS 8.8).
- cveCVE-2026-62823Heap-based buffer overflow allowing an unauthorized attacker to execute code over an adjacent network (CVSS 8.8).
- cveCVE-2026-62824Stack-based buffer overflow allowing an unauthorized attacker to execute code over a network (CVSS 8.8).
- cveCVE-2026-62830Missing authorization allowing an authorized attacker to elevate privileges over a network (CVSS 9.9).
- cveCVE-2026-62873Improper verification of cryptographic signature allowing an unauthorized attacker to elevate privileges over a network (CVSS 9.8).
- cveCVE-2026-62878Stack-based buffer overflow allowing an unauthorized attacker to execute code over a network (CVSS 9.8).
- cveCVE-2026-62893Use-after-free remote code execution vulnerability allowing an unauthorized attacker to execute code over a network (CVSS 9.8).
- cveCVE-2026-62896Improper authentication allowing an authorized attacker to elevate privileges over a network (CVSS 9.6).
- cveCVE-2026-62911Authentication bypass by capture-replay allowing an authorized attacker to elevate privileges over a network (CVSS 8.0).
- cveCVE-2026-63508Missing authentication for critical function allowing an unauthorized attacker to elevate privileges over a network (CVSS 10.0).
- cveCVE-2026-65665Deserialization of untrusted data allowing an authorized attacker to execute code over a network (CVSS 8.8).
- cveCVE-2026-65667Missing authorization allowing an unauthorized attacker to elevate privileges over a network (CVSS 10.0).
- cveCVE-2026-65791Heap-based buffer overflow allowing an unauthorized attacker to execute code over a network (CVSS 9.8).
- cveCVE-2026-68820Use-after-free elevation of privilege vulnerability exploited in the wild; allows a local authorized attacker to elevate privileges (CVSS 7.0).
- cveCVE-2026-68823Exposed dangerous method or function allowing an authorized attacker to execute code over a network (CVSS 9.1).
- cveCVE-2026-70332Cross-site scripting allowing an unauthorized attacker to perform spoofing over a network (CVSS 9.6).
Detection / Hunteropenrouter
What Happened
Microsoft published fixes for 421 security flaws in its August 2026 update, with 62 considered critical. One flaw in a core Windows networking component has already been used by attackers in the real world to gain elevated privileges on compromised machines. Organizations running Windows servers, Microsoft Office, SharePoint, Exchange, Remote Desktop, or Azure cloud services are affected. The risk is significant because many of the critical flaws allow remote attackers to execute code or take control without needing valid credentials. Organizations should apply the August 2026 patches as quickly as feasible, prioritizing internet-facing systems and the vulnerability already exploited in the wild.
Key Takeaways
- Microsoft released 421 vulnerabilities for August 2026, with 62 rated critical and 40 of those being remote code execution flaws.
- CVE-2026-68820, a use-after-free elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock, has been exploited in the wild.
- CVE-2026-62893 (Windows Deployment Services TFTP Server, CVSS 9.8) and CVE-2026-62878 (Windows DNS Server, CVSS 9.8) are critical RCE vulnerabilities Microsoft considers more or less likely to be exploited.
- Multiple Azure and cloud service vulnerabilities scored 9.9-10.0, including CVE-2026-56162 (Azure SQL Database, CVSS 10.0) and CVE-2026-63508 (Microsoft Planetary Computer Pro, CVSS 10.0).
- Talos released Snort rules (Snort 2: 1:66902-1:66948; Snort 3: 1:66902, 1:301589-1:301607) detecting exploitation attempts for some of the disclosed vulnerabilities.
Affected Systems
- Windows Ancillary Function Driver for WinSock
- Windows Deployment Services TFTP Server
- Microsoft SharePoint Server
- Windows DHCP Server
- Microsoft Excel
- Microsoft Exchange Server
- Microsoft Office
- Microsoft Office Word
- Microsoft Office Graphics Component
- Windows DNS Server
- Windows GDI+
- Windows Key Guard
- Windows Reliable Multicast Transport Driver (RMCAST)
- Windows Routing and Remote Access Service (RRAS)
- Windows Secure Socket Tunneling Protocol (SSTP)
- Windows iSCSI Target Service
- Windows Active Directory Certificate Services (AD CS)
- Windows Device Health Attestation (DHA)
- Remote Desktop Client
- Azure Active Directory
- Azure SQL Database
- Azure SQL Managed Instance
- Azure Service Bus
- Azure Logic Apps
- Azure Confidential Ledger
- Azure Entra ID
- Microsoft 365 Admin Center
- Microsoft Entra Provisioning Service
- Microsoft Teams
- Microsoft QUIC
- Microsoft Purview eDiscovery
- Microsoft Planetary Computer Pro
- Copilot Cowork
- Visual Studio Code
- GitHub Copilot
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock | High | Use-after-free elevation of privilege vulnerability exploited in the wild; allows a local authorized attacker to elevate privileges (CVSS 7.0). |
| CVE-2026-62893 | Windows Deployment Services TFTP Server | Critical | Use-after-free remote code execution vulnerability allowing an unauthorized attacker to execute code over a network (CVSS 9.8). |
| CVE-2026-65665 | Microsoft SharePoint Server | High | Deserialization of untrusted data allowing an authorized attacker to execute code over a network (CVSS 8.8). |
| CVE-2026-62823 | Windows DHCP Server | High | Heap-based buffer overflow allowing an unauthorized attacker to execute code over an adjacent network (CVSS 8.8). |
| CVE-2026-62878 | Windows DNS Server | Critical | Stack-based buffer overflow allowing an unauthorized attacker to execute code over a network (CVSS 9.8). |
| CVE-2026-62830 | Azure SRE Agent | Critical | Missing authorization allowing an authorized attacker to elevate privileges over a network (CVSS 9.9). |
| CVE-2026-50516 | Microsoft Azure Kubernetes Service | Critical | Missing authentication for critical function allowing an unauthorized attacker to elevate privileges over a network (CVSS 9.4). |
| CVE-2026-62911 | Microsoft Exchange Server | High | Authentication bypass by capture-replay allowing an authorized attacker to elevate privileges over a network (CVSS 8.0). |
| CVE-2026-62824 | Remote Desktop Client | High | Stack-based buffer overflow allowing an unauthorized attacker to execute code over a network (CVSS 8.8). |
| CVE-2026-62818 | Windows Active Directory Certificate Services (AD CS) | High | Use-after-free allowing an authorized attacker to execute code over a network (CVSS 8.8). |
| CVE-2026-62815 | Microsoft QUIC | Critical | Use-after-free allowing an unauthorized attacker to execute code over a network (CVSS 9.8). |
| CVE-2026-65791 | Windows iSCSI Target Service | Critical | Heap-based buffer overflow allowing an unauthorized attacker to execute code over a network (CVSS 9.8). |
| CVE-2026-56162 | Azure SQL Database | Critical | Improper authentication allowing an unauthorized attacker to elevate privileges over a network (CVSS 10.0). |
| CVE-2026-63508 | Microsoft Planetary Computer Pro | Critical | Missing authentication for critical function allowing an unauthorized attacker to elevate privileges over a network (CVSS 10.0). |
| CVE-2026-65667 | Microsoft Teams | Critical | Missing authorization allowing an unauthorized attacker to elevate privileges over a network (CVSS 10.0). |
| CVE-2026-50481 | Azure Active Directory | Critical | Modification of assumed-immutable data allowing an authorized attacker to elevate privileges over a network (CVSS 9.9). |
| CVE-2026-50515 | Azure Service Bus | Critical | Deserialization of untrusted data allowing an authorized attacker to execute code over a network (CVSS 9.9). |
| CVE-2026-59115 | Microsoft Entra Provisioning Service | Critical | Path traversal allowing an authorized attacker to elevate privileges over a network (CVSS 9.9). |
| CVE-2026-62873 | Microsoft 365 Admin Center | Critical | Improper verification of cryptographic signature allowing an unauthorized attacker to elevate privileges over a network (CVSS 9.8). |
| CVE-2026-56161 | Azure Logic Apps | Critical | Improper access control allowing an authorized attacker to disclose information over a network (CVSS 9.6). |
| CVE-2026-70332 | Microsoft Office SharePoint | Critical | Cross-site scripting allowing an unauthorized attacker to perform spoofing over a network (CVSS 9.6). |
| CVE-2026-62896 | Microsoft Teams | Critical | Improper authentication allowing an authorized attacker to elevate privileges over a network (CVSS 9.6). |
| CVE-2026-68823 | Azure Confidential Ledger | Critical | Exposed dangerous method or function allowing an authorized attacker to execute code over a network (CVSS 9.1). |
| CVE-2026-59118 | Copilot Cowork | Critical | Improper authorization allowing an unauthorized attacker to elevate privileges over a network (CVSS 9.3). |
Attack Chain
- Initial Access: Attacker establishes presence on a target network via phishing, exposed service exploitation, or existing compromise.
- Privilege Escalation: Attacker exploits CVE-2026-68820 (Windows AFD for WinSock use-after-free) to elevate from standard user to SYSTEM-level privileges locally.
- Lateral Movement / Network Exploitation: Attacker targets unpatched Windows server roles (DNS, DHCP, TFTP, AD CS, RRAS, SSTP, iSCSI) for remote code execution to move laterally across the network.
- Cloud Targeting: Attacker exploits Azure service vulnerabilities (Azure SQL, Azure Service Bus, Azure AD, Microsoft Teams) to escalate privileges or execute code in cloud-hosted infrastructure.
- Persistence and Impact: Attacker maintains access using elevated privileges and may exfiltrate data or deploy additional tooling.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: Yes
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Snort 2, Snort 3, Cisco Secure Firewall SRU
Talos released Snort rules detecting exploitation attempts for a subset of the August 2026 Patch Tuesday vulnerabilities. Snort 2 rule IDs: 1:66902-1:66910, 1:66912-1:66923, 1:66929-1:66932, 1:66935-1:66948. Snort 3 rule IDs: 1:66902, 1:301589-1:301607. Cisco Secure Firewall customers should update their SRU; open-source Snort subscribers can download the latest rule pack from Snort.org.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can detect post-exploitation behavior following successful vulnerability exploitation, such as privilege escalation attempts via CVE-2026-68820 or unusual process activity on server roles. However, the initial exploitation of memory corruption vulnerabilities in kernel-mode drivers and network services may not produce clear EDR telemetry. |
| Network Visibility | High | Talos Snort rules provide network-level detection for exploitation attempts against several disclosed vulnerabilities. Network traffic to affected server roles (DNS, DHCP, TFTP, iSCSI, RRAS, SSTP) and Azure services can be monitored for anomalous patterns. |
| Detection Difficulty | Moderate | Snort rules are available for network-level detection. Host-level detection of exploitation for kernel driver and service vulnerabilities requires specific log sources and may produce false positives from legitimate administrative activity. Cloud service vulnerabilities require Azure/M365 audit log visibility. |
Required Log Sources
- Windows Event Logs (Security, System, Application)
- DNS server logs
- DHCP server logs
- Network IDS/IPS logs (Snort/Suricata)
- Azure Activity Logs
- Microsoft 365 audit logs
- EDR process and file operation telemetry
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Look for processes attempting to interact with the Windows Ancillary Function Driver for WinSock in unusual ways, which may indicate exploitation of CVE-2026-68820 for local privilege escalation. | EDR process telemetry, Windows Event Logs (System), driver object access logs | Privilege Escalation | Medium — legitimate network diagnostic or security tools may interact with WinSock components. |
| Hunt for anomalous network traffic patterns targeting Windows DNS Server, DHCP Server, or TFTP Server ports that may indicate exploitation attempts against the critical RCE vulnerabilities disclosed this month. | Network IDS/IPS logs, firewall logs, NetFlow data | Initial Access / Lateral Movement | Low — unusual traffic to these specific service ports from non-trusted sources is suspicious. |
| Monitor Azure Activity Logs for privilege escalation patterns in Azure SQL Database, Azure Service Bus, or Azure AD that may indicate exploitation of the cloud vulnerabilities disclosed this month. | Azure Activity Logs, Microsoft 365 audit logs, Azure Defender alerts | Privilege Escalation / Cloud Exploitation | Medium — legitimate administrative changes may resemble privilege escalation activity. |
| Look for unexpected code execution or process spawning on systems running Microsoft SharePoint Server, which may indicate exploitation of CVE-2026-65665 (deserialization RCE) or CVE-2026-63520. | EDR process telemetry, IIS logs, SharePoint ULS logs | Execution | Medium — SharePoint application pools may spawn worker processes as part of normal operation. |
Control Gaps
- Signature-based AV will not detect exploitation of memory corruption vulnerabilities in kernel drivers or network services.
- Host-based firewalls may not block traffic to required service ports on internal networks where DHCP, DNS, TFTP, or iSCSI are expected.
- Cloud security posture management tools may not detect exploitation of authentication bypass or missing authorization vulnerabilities in Azure services without specific alerting rules.
Key Behavioral Indicators
- Unexpected child processes spawned by Windows service host processes (svchost.exe) hosting DNS, DHCP, or TFTP services
- Anomalous network connections to TCP/UDP ports associated with iSCSI (3260), TFTP (69), or SSTP (443) from non-administrative hosts
- Privilege escalation events following process execution from standard user contexts on systems where CVE-2026-68820 exploitation is possible
- Unexpected process execution within SharePoint IIS application pools
- Azure Activity Log entries showing role assignment or privilege changes from unexpected principals or IP addresses
False Positive Assessment
Medium — Network-based Snort rules for service exploitation may trigger on legitimate administrative or diagnostic traffic to DNS, DHCP, or TFTP services. Host-based detections for privilege escalation via WinSock driver interaction may produce false positives from security or network management tools.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Prioritize patching for CVE-2026-68820, which has been exploited in the wild, on all Windows endpoints and servers.
- Consider applying the August 2026 Microsoft security updates to internet-facing Windows servers running DNS, DHCP, TFTP, AD CS, RRAS, SSTP, and iSCSI services as quickly as feasible.
- If patching is delayed, evaluate whether network segmentation can isolate affected server roles from untrusted network segments.
- If your organization uses Snort or Cisco Secure Firewall, consider updating to the latest SRU or Snort rule pack to gain network-level detection for exploitation attempts.
Infrastructure Hardening
- Evaluate whether Windows Deployment Services TFTP Server, Windows DHCP Server, and Windows DNS Server are exposed to untrusted or adjacent networks; consider restricting access via firewall rules where supported.
- Review Azure service configurations for Azure SQL Database, Azure Service Bus, Azure Active Directory, and Microsoft Teams to verify authentication and authorization controls are properly enforced.
- Consider enabling enhanced logging on Windows server roles (DNS, DHCP, AD CS) to improve detection visibility for exploitation attempts.
- If applicable, evaluate whether Remote Desktop Client and Remote Desktop Services can be restricted to require NLA and VPN access only.
User Protection
- Consider deploying the August 2026 Office updates to all endpoints running Microsoft Excel, Word, or other Office components to address local RCE vulnerabilities.
- If your organization uses Microsoft Teams, consider applying the relevant patches to address the critical elevation of privilege and spoofing vulnerabilities.
- Evaluate whether Visual Studio Code and GitHub Copilot extensions in use are affected by the disclosed security feature bypass and elevation of privilege vulnerabilities.
Security Awareness
- Consider reminding users to avoid opening unexpected Office documents from untrusted sources, as multiple Office RCE vulnerabilities were disclosed this month.
- If applicable, reinforce existing guidance on reporting suspicious SharePoint or Teams activity, given the authentication bypass and spoofing vulnerabilities disclosed.