Microsoft's August 2026 Patch Tuesday addresses 421 vulnerabilities including 62 rated critical. One vulnerability, CVE-2026-68820 (Windows Ancillary Function Driver for WinSock, CVSS 7.0), has been exploited in the wild as a local elevation of privilege flaw. Critical RCE vulnerabilities span Windows server components (DNS, DHCP, TFTP, AD CS, RRAS, SSTP, iSCSI), desktop applications (Office, Excel, SharePoint, Remote Desktop Client), and cloud services (Azure SQL, Azure Service Bus, Azure AD, Microsoft Teams). Talos released Snort rules providing network-level detection for exploitation attempts against a subset of these vulnerabilities.
Snort
2 posts
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft's July 2026 Patch Tuesday discloses 622 vulnerabilities, including 57 critical-severity issues spanning RCE, elevation of privilege, spoofing, and security feature bypass across Windows components, Office, SharePoint, SQL Server, Dynamics, and cloud services. Two vulnerabilities — an AD FS elevation of privilege flaw (CVE-2026-56155) and a SharePoint spoofing flaw (CVE-2026-56164) — are confirmed exploited in the wild, and 11 critical RCE issues plus several important EoP flaws are rated 'more likely' to be exploited by Microsoft. Cisco Talos has released Snort 2 and Snort 3 rule updates to detect exploitation attempts for a subset of the disclosed vulnerabilities.