Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft's July 2026 Patch Tuesday discloses 622 vulnerabilities, including 57 critical-severity issues spanning RCE, elevation of privilege, spoofing, and security feature bypass across Windows components, Office, SharePoint, SQL Server, Dynamics, and cloud services. Two vulnerabilities — an AD FS elevation of privilege flaw (CVE-2026-56155) and a SharePoint spoofing flaw (CVE-2026-56164) — are confirmed exploited in the wild, and 11 critical RCE issues plus several important EoP flaws are rated 'more likely' to be exploited by Microsoft. Cisco Talos has released Snort 2 and Snort 3 rule updates to detect exploitation attempts for a subset of the disclosed vulnerabilities.
Detection / HunterAnthropic
What Happened
Microsoft released its monthly batch of security fixes covering 622 different flaws in Windows and related products, with 57 of them classified as the most severe kind. Businesses and individuals using Windows, Microsoft Office, SharePoint, SQL Server, Exchange, and several other Microsoft products are affected. This matters because two of these flaws are already being actively exploited by attackers, and many others could allow attackers to take over systems remotely just by getting a user to open a malicious file or by reaching a vulnerable service over the network. Organizations should apply Microsoft's July 2026 security updates as soon as possible, prioritizing the flaws confirmed as actively exploited and those Microsoft says are 'more likely' to be targeted.
Key Takeaways
- Microsoft's July 2026 Patch Tuesday addresses 622 vulnerabilities, 57 of which are rated critical.
- Two vulnerabilities (CVE-2026-56155 in AD FS and CVE-2026-56164 in SharePoint) are confirmed by Microsoft to have been exploited in the wild.
- 48 of the critical vulnerabilities are remote code execution (RCE) flaws spanning Windows core components, Office, SQL Server, SharePoint, and Dynamics products.
- Eleven critical RCE vulnerabilities are rated 'more likely' to be exploited, including heap-based buffer overflows in DHCP Server/Client, Windows Media, MSMQ, and deserialization flaws in SharePoint and Dynamics NAV.
- Cisco Talos has released new Snort 2 and Snort 3 rule sets to detect exploitation attempts against a subset of the disclosed vulnerabilities.
Affected Systems
- Active Directory Federation Services (AD FS)
- Microsoft SharePoint Server
- Windows DHCP Client and Server service
- Windows Media and Media Foundation
- Microsoft Office, Word, Excel, PowerPoint
- Windows GDI and GDI+
- DirectX Graphics Kernel
- Microsoft SQL Server
- Windows Reliable Multicast Transport Driver (RMCAST)
- Windows TCP/IP
- Windows Server Network driver
- Windows Print Spooler
- Windows Secure Socket Tunneling Protocol (SSTP)
- Windows Active Directory Domain Services
- Microsoft Defender
- Microsoft Copilot
- Microsoft Message Queuing (MSMQ)
- Remote Desktop Client
- Microsoft Dynamics NAV and Dynamics 365 Business Central (on-premises)
- Minecraft Bedrock Dedicated Server
- Windows Secure Kernel Mode
- Windows Server Update Service (WSUS)
- Windows Hyper-V
- Active Directory Certificate Services
- Microsoft Windows VMSwitch
- Microsoft Exchange Server
- Microsoft Edge (Chromium-based)
- Windows Admin Center (WAC)
- Windows Boot Loader
- Windows Kernel
- Windows Win32k
- Azure Synapse, Azure OpenAI, Exchange Online, Entra (cloud services)
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-56155 | Active Directory Federation Services (AD FS) | Important | Insufficient granularity of access control allows an authorized attacker to elevate privileges locally; confirmed exploited in the wild. |
| CVE-2026-56164 | Microsoft SharePoint Server | Moderate | Missing authentication for a critical function allows an unauthorized attacker to perform spoofing over a network; confirmed exploited in the wild. |
| CVE-2026-50370 | Windows DHCP Server service | Critical | Heap-based buffer overflow exploitable by an unauthorized attacker over an adjacent network; rated more likely to be exploited. |
| CVE-2026-50518 | Windows DHCP Server service | Critical | Heap-based buffer overflow exploitable by an unauthorized attacker over a network; rated more likely to be exploited. |
| CVE-2026-54128 | Windows DHCP client | Critical | Use-after-free allowing an unauthorized attacker to execute code locally; rated more likely to be exploited. |
| CVE-2026-50327 | Windows Media | Critical | Heap-based buffer overflow; rated more likely to be exploited. |
| CVE-2026-50655 | Windows Media Foundation | Critical | Heap-based buffer overflow; rated more likely to be exploited. |
| CVE-2026-54992 | Microsoft Message Queuing Queue Manager | Critical | Heap-based buffer overflow; rated more likely to be exploited. |
| CVE-2026-56188 | Windows Server Network driver | Critical | Race condition; rated more likely to be exploited. |
| CVE-2026-55010 | Minecraft Bedrock Dedicated Server | Critical | Heap-based buffer overflow exploitable over a network by an unauthorized attacker; rated more likely to be exploited. |
| CVE-2026-50522 | Microsoft SharePoint | Critical | Deserialization vulnerability allowing an unauthorized attacker to execute code over a network; rated more likely to be exploited. |
| CVE-2026-58644 | Microsoft SharePoint | Critical | Deserialization vulnerability allowing an unauthorized attacker to execute code over a network; rated more likely to be exploited. |
| CVE-2026-55944 | Microsoft Dynamics NAV / Dynamics 365 Business Central (on-premises) | Critical | Deserialization vulnerability allowing an unauthorized attacker to execute code over a network; rated more likely to be exploited. |
| CVE-2026-55008 | Microsoft Exchange Server | Critical | Cross-site scripting condition enabling spoofing; rated more likely to be exploited. |
| CVE-2026-55040 | Microsoft SharePoint Server | Critical | Weak authentication enabling a security feature bypass; rated more likely to be exploited. |
| CVE-2026-49170 | Windows StateRepository API Server | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-49795 | Windows Kernel | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-49798 | Windows Kernel | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-49805 | Win32k | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50297 | Win32k | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50325 | Win32k | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50329 | Microsoft DWM Core Library | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50332 | Windows Kernel | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50343 | Microsoft Install Service | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50351 | Windows Audio Compression Manager (ACM) | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50375 | DirectX Graphics Kernel | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50387 | Windows GDI | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50390 | Windows Kernel | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50423 | Windows Kernel | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50433 | Windows Media | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50436 | Windows Kernel | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50454 | Windows User Interface Core | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50475 | Windows Kernel | Important | Information disclosure vulnerability rated more likely to be exploited. |
| CVE-2026-50476 | Windows Network Connections Service | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50489 | Win32k | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50509 | Wireless Wide Area Network Service (WwanSvc) | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50667 | Windows Common Log File System Driver | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-50688 | Windows Win32k | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-54114 | Windows Win32k | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-54986 | Windows Win32k | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-57091 | Windows File History Service | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-58531 | Windows SMB | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-58536 | Windows Cloud Files Mini Filter Driver | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-58596 | Microsoft Edge (Chromium-based) | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-58631 | Windows Admin Center (WAC) | Important | Remote code execution vulnerability rated more likely to be exploited. |
| CVE-2026-58633 | Desktop Window Manager | Important | Elevation of privilege vulnerability rated more likely to be exploited. |
| CVE-2026-58638 | Windows Boot Loader | Important | Security feature bypass vulnerability rated more likely to be exploited. |
Attack Chain
- Initial Access/Trigger: Attacker delivers a specially crafted document (Office/Word/PowerPoint) or reaches a vulnerable network service (DHCP, SharePoint, SMB, SSTP, etc.).
- Exploitation: Vulnerability class (heap overflow, use-after-free, deserialization, missing authentication, race condition) is triggered to gain code execution or elevated privileges.
- Privilege Escalation: Local elevation of privilege flaws in Windows Kernel, Win32k, Hyper-V, or AD FS are leveraged to gain SYSTEM or administrative rights.
- Impact: Attacker achieves remote code execution, spoofing, or security feature bypass depending on the specific CVE, potentially leading to further compromise of the host or domain.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: Yes
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Snort.org, Cisco Secure Firewall SRU
Cisco Talos has released Snort 2 (SID ranges 66733-66743, 66745-66785, 66791-66793, 66800-66807) and Snort 3 (SID ranges 301555-301579, 301581-301583) rules covering exploitation attempts against a subset of the disclosed vulnerabilities. Rule content is not reproduced here; refer to Snort.org or the Cisco Secure Firewall SRU update for details.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | Exploitation of document-based RCEs (Office/Word/PowerPoint) and local privilege escalation flaws (Kernel, Win32k) would typically generate process, memory, and behavioral telemetry visible to EDR, but network-facing service exploits (DHCP, SharePoint, SMB) may require additional network-layer visibility. |
| Network Visibility | Medium | Several critical flaws (DHCP Server/Client, SharePoint, SSTP, SMB, TCP/IP) are exploitable over a network or adjacent network, making network IDS/IPS signatures such as the released Snort rules relevant, but visibility depends on whether the affected services are exposed and monitored. |
| Detection Difficulty | Hard | Many of the vulnerabilities are memory-corruption or deserialization issues that can be exploited with crafted inputs leaving minimal artifacts prior to code execution, and the sheer volume (622 CVEs) makes prioritization and comprehensive detection engineering challenging. |
Required Log Sources
- Windows Event Logs (Security, Application)
- Sysmon process creation and network connection events
- DHCP server/client logs
- IIS/SharePoint application logs
- Network IDS/IPS alerts (Snort)
- Endpoint EDR telemetry for crash/exploitation patterns
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Look for unexpected child processes spawned from Office applications (Word, Excel, PowerPoint) shortly after opening an externally-sourced document, which could indicate exploitation of a document-parsing RCE. | EDR process ancestry and command-line logging | Execution (T1203) | Medium - legitimate macros or add-ins can also spawn child processes. |
| Monitor for crashes or anomalous restarts of the DHCP Server/Client service, Windows Media components, or MSMQ, which could indicate attempted exploitation of heap-based buffer overflow vulnerabilities. | Windows Event Logs (Application/System), service crash dumps | Initial Access/Exploitation (T1190) | Low - unexplained service crashes are uncommon in stable environments. |
| Consider hunting for unusual local privilege escalation patterns, such as low-privileged processes suddenly obtaining SYSTEM-level access, which could indicate exploitation of Windows Kernel or Win32k elevation of privilege flaws. | EDR privilege/token change events, Windows Security Event ID 4672/4688 | Privilege Escalation (T1068) | Medium - legitimate administrative tools can trigger similar token elevation. |
| Review SharePoint server logs for anomalous deserialization-related requests or authentication bypass attempts consistent with the reported spoofing/security feature bypass vulnerabilities. | IIS/SharePoint application logs, WAF logs | Initial Access (T1190) | Medium - complex SharePoint workflows can produce similar anomalous request patterns. |
| Deploy and monitor the newly released Talos Snort signatures against network traffic to detect exploitation attempts targeting the disclosed CVEs, especially on exposed DHCP, SharePoint, and SMB services. | Network IDS/IPS alert logs | Exploitation (T1190/T1203) | Low - signature-based detections are generally low-noise if rules are well-tuned. |
Control Gaps
- Signature-based network detection alone will not catch zero-day or unpatched exploitation prior to rule release.
- Endpoint antivirus without behavioral/exploit-mitigation capability may miss in-memory exploitation of heap overflow and use-after-free vulnerabilities.
- Perimeter firewalls without deep packet inspection may not detect exploitation of internal-only services like DHCP or SMB.
Key Behavioral Indicators
- Office application spawning unexpected child processes after document open
- Unexplained crashes or restarts of DHCP, Windows Media, or MSMQ services
- Sudden privilege elevation of a previously low-privileged process or user session
- Anomalous authentication or deserialization patterns in SharePoint/Exchange logs
False Positive Assessment
Low - the article is a vendor patch summary and rule release notice rather than an active campaign report; associated Snort detections are signature-based and expected to be low-noise when properly tuned.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting, then prioritize patching CVE-2026-56155 and CVE-2026-56164 given confirmed in-the-wild exploitation.
- Evaluate applying Microsoft's July 2026 security updates for all 57 critical vulnerabilities as soon as feasible, prioritizing those rated 'more likely' to be exploited.
- Consider deploying the newly released Talos Snort rules on applicable network sensors if your environment uses Snort-based IDS/IPS.
Infrastructure Hardening
- Evaluate whether DHCP Server/Client, SharePoint, SQL Server, and SSTP services are exposed to untrusted networks and restrict access where not required.
- Consider network segmentation to limit exposure of internal services (DHCP, SMB, RMCAST) that are affected by remotely exploitable critical vulnerabilities.
- Review and harden AD FS and Active Directory Certificate Services configurations given the exploited AD FS flaw and critical AD CS EoP vulnerability.
User Protection
- If your EDR supports exploit protection or attack surface reduction rules, consider enabling them for Office applications to mitigate document-based RCE risks.
- Evaluate enabling Protected View or similar sandboxing for documents received from external or untrusted sources.
- Consider deploying endpoint patch management tooling to ensure timely rollout of the July 2026 updates across all endpoints.
Security Awareness
- Consider reinforcing user awareness around opening unsolicited or unexpected Office documents, given the number of critical Office/Word/PowerPoint RCE flaws this month.
- Include patch management cadence and Patch Tuesday awareness as part of ongoing security training for IT and operations staff.