news.mlab.sh
Back to the feed
vulnerability

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

High
Summary

Microsoft released its July 2026 security update, containing 622 vulnerabilities, with 57 classified as critical. Several of these, including those affecting Active Directory Federation Services, SharePoint Server, and various Windows services, have been exploited in the wild. Cisco Talos is releasing a new Snort ruleset to address these exploits. The update includes a wide range of RCE and EoP vulnerabilities impacting products like Windows Media, DHCP Server, SQL Server, Defender, and Copilot, alongside spoofing and security feature bypass vulnerabilities. The release highlights a significant number of cloud-based vulnerabilities affecting Microsoft services.

Microsoft has released its monthly security update for July 2026, encompassing 622 vulnerabilities impacting a diverse range of products, including 57 classified as "critical." The update addresses security concerns across Windows, SharePoint, SQL Server, Defender, Copilot, and other Microsoft services.

Two of the vulnerabilities disclosed this month have been exploited in the wild. CVE-2026-56155 is a privilege escalation vulnerability in Active Directory Federation Services (AD FS) caused by insufficient access control granularity, allowing an attacker to elevate privileges locally. CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server due to missing authentication for a critical function, enabling spoofing over a network.

The 57 "critical" entries break down as follows: 48 remote code execution (RCE), seven elevation of privilege (EoP), one spoofing, and one security feature bypass vulnerability. The RCE vulnerabilities affect a wide array of Microsoft services and applications, including Windows Media and Media Foundation, the Windows DHCP client and DHCP Server service, Microsoft Office, Word, Excel and PowerPoint, Windows GDI and GDI+, DirectX Graphics Kernel, Microsoft SharePoint, Microsoft SQL Server, the Windows Reliable Multicast Transport Driver (RMCAST), Windows TCP/IP, the Windows Print Spooler, the Windows Secure Socket Tunneling Protocol (SSTP), Windows Active Directory Domain Services, Microsoft Defender, Microsoft Copilot, Microsoft Message Queuing (MSMQ), the Remote Desktop Client, Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (on-premises), and the Minecraft Bedrock Dedicated Server.

Eleven of the critical RCE vulnerabilities are rated "more likely" to be exploited. CVE-2026-50370 and CVE-2026-50518 are heap-based buffer overflows in the Windows DHCP Server service, exploitable by an unauthorized attacker over an adjacent network and over a network, respectively. CVE-2026-54128 is a use-after-free in the Windows DHCP client that allows an unauthorized attacker to execute code locally. CVE-2026-50327 and CVE-2065-50655 are heap-based buffer overflows in Windows Media and Windows Media Foundation. CVE-2026-54992 is a heap-based buffer overflow in the Microsoft Message Queuing Queue Manager. CVE-2026-56188 is a race condition in the Windows Server Network driver, and CVE-2026-55010 is a heap-based buffer overflow in the Minecraft Bedrock Dedicated Server that an unauthorized attacker could exploit over a network.

Several of the critical entries — including Copilot, Azure Synapse, Azure OpenAI, Exchange Online and Entra items — affect Microsoft cloud services, for which Microsoft has not assigned an exploitation-likelihood rating.

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely": CVE-2026-49170: Windows StateRepository API Server file Elevation of Privilege Vulnerability; CVE-2026-49795: Windows Kernel Elevation of Privilege Vulnerability; CVE-2026-49798: Windows Kernel Elevation of Privilege Vulnerability; CVE-2026-49805: Win32k Elevation of Privilege Vulnerability; CVE-2026-50297: Win32k Elevation of Privilege Vulnerability; CVE-2026-50325: Win32k Elevation of Privilege Vulnerability; CVE-2026-50332: Microsoft DWM Core Library Elevation of Privilege Vulnerability; CVE-2026-50343: Windows Install Service Elevation of Privilege Vulnerability; CVE-2026-50351: Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability; CVE-2026-50375: DirectX Graphics Kernel Elevation of Privilege Vulnerability; CVE-2026-50387: Windows GDI Elevation of Privilege Vulnerability; CVE-2026-50390: Windows Kernel Elevation of Privilege Vulnerability; CVE-2026-50423: Windows Kernel Elevation of Privilege Vulnerability; CVE-2026-50433: Windows Media Elevation of Privilege Vulnerability; CVE-2026-50436: Windows Kernel Elevation of Privilege Vulnerability; CVE-2026-50454: Windows User Interface Core Elevation of Privilege Vulnerability; CVE-2026-50475: Windows Kernel Information Disclosure Vulnerability; CVE-2026-50476: Windows Network Connections Service Elevation of Privilege Vulnerability; CVE-2026-50489: Win32k Elevation of Privilege Vulnerability; CVE-2026-50509: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability; CVE-2026-50667: Windows Common Log File System Driver Elevation of Privilege Vulnerability; CVE-2026-50688: Windows Win32k Elevation of Privilege Vulnerability; CVE-2026-54114: Windows Win32k Elevation of Privilege Vulnerability; CVE-2026-54986: Windows Win32k Elevation of Privilege Vulnerability; CVE-2026-57091: Windows File History Service Elevation of Privilege Vulnerability; CVE-2026-58531: Windows SMB Elevation of Privilege Vulnerability; CVE-2026-58536: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability; CVE-2026-58631: Windows Admin Center (WAC) Remote Code Execution Vulnerability; CVE-2026-58633: Desktop Window Manager Elevation of Privilege Vulnerability; CVE-2026-58638: Windows Boot Loader Security Feature Bypass Vulnerability.

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org. The following Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are: 1:66733 - 1:66743, 1:66745 - 1:66785, 1:66791 - 1:66793, 1:66800 - 1:66807. The following Snort 3 rules are also available: 1:301555 - 1:301579, 1:301581 - 1:301583.

Read the full article at Cisco Talos