Visualização normal

Antes de ontemCyber Threat Intel
  • ✇Malwarebytes
  • Patch Tuesday: Update now to fix 421 flaws, including three zero-days
    Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of-co
     

Patch Tuesday: Update now to fix 421 flaws, including three zero-days

12 de Agosto de 2026, 10:48

Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges.

The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of-concept (PoC), a newly completed unauthenticated SharePoint remote code execution (RCE) chain, and a potentially wormable Windows DNS Server flaw.

How to apply patches and check if you’re protected

These updates fix security problems and help keep your Windows PC protected. Here’s how to make sure you’re up to date:

  • Click the Start button, then open Settings.
  • Select Windows Update (usually at the bottom of the menu on the left).
  • Click Check for updates. Windows will search for the latest security updates. If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately to complete the update. Otherwise, continue to the next step.
Windows update history - August 12, 2026
  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.
  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Windows up to date

Technical details

Windows Deployment Services (WDS) users should prioritize CVE-2026-62893 (CVSS score 9.8 out of 10), an unauthenticated RCE flaw in the TFTP (Trivial File Transfer Protocol) server. TFTP normally runs on UDP port 69 and has no built-in authentication. It is primarily an enterprise and school network issue, but it could enable lateral movement where WDS is deployed.

Microsoft also fixed CVE-2026-62832, a publicly disclosed elevation of privilege (EoP) vulnerability in the Windows User Profile Service. It maps to the issue researchers called LegacyHive, for which a limited public proof of concept was released in July.

The PoC demonstrates how a local authenticated attacker could abuse the service’s registry hive handling to load another user’s hive, potentially including an administrator’s. The released demonstration is deliberately constrained and requires credentials for another user, but the availability of code and the broad Windows footprint make this one a strong candidate for exploitation attempts.

Another good reason to promptly update is the number (I counted 48) of remote code execution (RCE) fixes for Office applications and components, including Excel, Word, Outlook, PowerPoint, and the Office graphics component. Document-borne vulnerabilities are attractive to phishing operators because email attachments and shared documents provide delivery mechanisms that people are likely to open.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities Cisco Talos
    Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This
     

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

11 de Agosto de 2026, 19:21
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical." 

Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild 

CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This vulnerability has a CVSS base score of 7.0. 

Out of 62 "critical" vulnerabilities, 40 are remote code execution (RCE) vulnerabilities. 

Microsoft considers exploitation of the following vulnerabilities more likely. 

CVE-2026-62893 is a remote code execution vulnerability affecting Windows Deployment Services TFTP Server. A Use After Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.8. 

CVE-2026-65665 is a remote code execution vulnerability affecting Microsoft SharePoint Server. Deserialization of Untrusted Data could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62823 is a remote code execution vulnerability affecting Windows DHCP Server. A Heap-based Buffer Overflow could allow an unauthorized attacker to execute code over an adjacent network. This vulnerability has a CVSS base score of 8.8. 

Microsoft considers exploitation of the following vulnerabilities less likely. 

CVE-2026-62830 is an elevation of privilege vulnerability affecting Azure SRE Agent. Missing Authorization could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-50516 is an elevation of privilege vulnerability affecting Microsoft Azure Kubernetes Service. Missing Authentication for Critical Function could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.4. 

Three remote code execution vulnerabilities, CVE-2026-68794CVE-2026-68816 and CVE-2026-68804, affect Microsoft Excel and have a CVSS base score of 7.8. An unauthorized attacker could execute code locally. CVE-2026-68794 is a Heap-based Buffer Overflow. CVE-2026-68816 is a Stack-based Buffer Overflow. CVE-2026-68804 involves a Numeric Truncation Error and a Heap-based Buffer Overflow. 

CVE-2026-62911 is an elevation of privilege vulnerability affecting Microsoft Exchange Server. Authentication Bypass by Capture-replay could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.0. 

Nine remote code execution vulnerabilities, CVE-2026-63515CVE-2026-65657CVE-2026-63532CVE-2026-64898CVE-2026-64903CVE-2026-64909CVE-2026-64910CVE-2026-64911 and CVE-2026-70130, affect Microsoft Office and could allow an unauthorized attacker to execute code locally. CVE-2026-63515 involves an Out-of-bounds Read and an Integer Underflow (Wrap or Wraparound) and has a CVSS base score of 7.8. CVE-2026-65657 is a Use After Free and has a CVSS base score of 7.8. CVE-2026-63532 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-64898 involves a Heap-based Buffer Overflow and an Integer Overflow or Wraparound and has a CVSS base score of 7.8. CVE-2026-64903 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-64909 involves an Integer Underflow (Wrap or Wraparound), an Out-of-bounds Read and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-64910 is an Untrusted Pointer Dereference and has a CVSS base score of 7.8. CVE-2026-64911 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow and has a CVSS base score of 7.8. CVE-2026-70130 is a Heap-based Buffer Overflow and has a CVSS base score of 8.4. 

Five remote code execution vulnerabilities, CVE-2026-63513CVE-2026-63519CVE-2026-65664CVE-2026-63526 and CVE-2026-66807, affect Microsoft Office Graphics Component and have a CVSS base score of 7.8. An unauthorized attacker could execute code locally. CVE-2026-63513 is a Heap-based Buffer Overflow. CVE-2026-63519 is a Heap-based Buffer Overflow. CVE-2026-65664 is a Heap-based Buffer Overflow. CVE-2026-63526 is a Stack-based Buffer Overflow. CVE-2026-66807 is a Stack-based Buffer Overflow. 

Three remote code execution vulnerabilities, CVE-2026-63518CVE-2026-63525 and CVE-2026-64907, affect Microsoft Office Word and have a CVSS base score of 7.8. An unauthorized attacker could execute code locally. CVE-2026-63518is a Heap-based Buffer Overflow. CVE-2026-63525 is a Numeric Truncation Error. CVE-2026-64907 is a Stack-based Buffer Overflow.https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62827 

Two elevation of privilege vulnerabilities, CVE-2026-62827 and CVE-2026-64921, affect Microsoft SharePoint Server and have a CVSS base score of 8.8. An authorized attacker could elevate privileges over a network. CVE-2026-62827involves Improper Authentication. CVE-2026-64921 involves Missing Authentication for Critical Function. 

CVE-2026-62824 is a remote code execution vulnerability affecting Remote Desktop Client. A Stack-based Buffer Overflow could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62818 is a remote code execution vulnerability affecting Windows Active Directory Certificate Services (AD CS). A Use After Free could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.8. 

Three remote code execution vulnerabilities, CVE-2026-62817CVE-2026-62820 and CVE-2026-62878, affect Windows DNS Server. CVE-2026-62817 is an Out-of-bounds Write that could allow an unauthorized attacker to execute code over an adjacent network and has a CVSS base score of 8.8. CVE-2026-62820 involves Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition'), could allow an unauthorized attacker to execute code over a network and has a CVSS base score of 8.1. CVE-2026-62878 is a Stack-based Buffer Overflow that could allow an unauthorized attacker to execute code over a network and has a CVSS base score of 9.8. 

Two remote code execution vulnerabilities, CVE-2026-66802 and CVE-2026-71331, affect Windows Device Health Attestation (DHA), could allow an unauthorized attacker to execute code over a network and have a CVSS base score of 8.1. CVE-2026-66802 involves Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and a Use After Free. CVE-2026-71331 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow. 

Two remote code execution vulnerabilities, CVE-2026-62890 and CVE-2026-62822, affect Windows GDI+. CVE-2026-62890 is a Heap-based Buffer Overflow that could allow an authorized attacker to execute code locally and has a CVSS base score of 7.8. CVE-2026-62822 involves an Integer Overflow or Wraparound and a Heap-based Buffer Overflow, could allow an unauthorized attacker to execute code over a network and has a CVSS base score of 8.8. 

CVE-2026-66799 is an elevation of privilege vulnerability affecting Windows Key Guard. A Heap-based Buffer Overflow could allow an authorized attacker to elevate privileges locally. This vulnerability has a CVSS base score of 7.8. 

CVE-2026-62816 is a remote code execution vulnerability affecting Windows Reliable Multicast Transport Driver (RMCAST). A Heap-based Buffer Overflow and an Integer Overflow or Wraparound could allow an unauthorized attacker to execute code over an adjacent network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62819 is a remote code execution vulnerability affecting Windows Routing and Remote Access Service (RRAS). A Use After Free could allow an attacker to gain unauthorized access to a victim's machine. This vulnerability has a CVSS base score of 8.1. 

CVE-2026-62889 is a remote code execution vulnerability affecting Windows Secure Socket Tunneling Protocol (SSTP). A Double Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.1. 

Microsoft considers exploitation of the following vulnerabilities unlikely. 

CVE-2026-65789 is a remote code execution vulnerability affecting Windows DNS Server. A Use After Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 8.1. 

CVE-2026-65791 is a remote code execution vulnerability affecting Windows iSCSI Target Service. A Heap-based Buffer Overflow could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.8. 

Other critical vulnerabilities 

CVE-2026-49163 is an elevation of privilege vulnerability affecting Application Insights Profiler. Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-50481 is an elevation of privilege vulnerability affecting Azure Active Directory. Modification of Assumed-Immutable Data (MAID) could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-68823 is a remote code execution vulnerability affecting Azure Confidential Ledger. Exposed Dangerous Method or Function could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.1. 

CVE-2026-62869 affects Azure Entra ID. Insufficient Verification of Data Authenticity could allow an authorized attacker to perform spoofing over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-56161 is an information disclosure vulnerability affecting Azure Logic Apps. Improper Access Control could allow an authorized attacker to disclose information over a network. This vulnerability has a CVSS base score of 9.6. 

Two elevation of privilege vulnerabilities, CVE-2026-63522 and CVE-2026-56162, affect Azure SQL Database. CVE-2026-63522 involves Incorrect Permission Assignment for Critical Resource, could allow an authorized attacker to elevate privileges locally and has a CVSS base score of 7.8. CVE-2026-56162 involves Improper Authentication, could allow an unauthorized attacker to elevate privileges over a network and has a CVSS base score of 10.0. 

CVE-2026-62836 is an elevation of privilege vulnerability affecting Azure SQL Managed Instance. Improper Restriction of Communication Channel to Intended Endpoints could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.7. 

CVE-2026-50515 is a remote code execution vulnerability affecting Azure Service Bus. Deserialization of Untrusted Data could allow an authorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-62873 is an elevation of privilege vulnerability affecting Microsoft 365 Admin Center. Improper Verification of Cryptographic Signature could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.8. 

CVE-2026-59115 is an elevation of privilege vulnerability affecting Microsoft Entra Provisioning Service. Path Traversal: '.../...//' could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.9. 

CVE-2026-70332 affects Microsoft Office SharePoint. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') could allow an unauthorized attacker to perform spoofing over a network. This vulnerability has a CVSS base score of 9.6. 

CVE-2026-63508 is an elevation of privilege vulnerability affecting Microsoft Planetary Computer Pro. Missing Authentication for Critical Function could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 10.0. 

CVE-2026-59118 is an elevation of privilege vulnerability affecting Copilot Cowork. Improper Authorization could allow an unauthorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 9.3. 

CVE-2026-65668 is an elevation of privilege vulnerability affecting Microsoft Purview eDiscovery. Improper Access Control could allow an authorized attacker to elevate privileges over a network. This vulnerability has a CVSS base score of 8.8. 

CVE-2026-62815 is a remote code execution vulnerability affecting Microsoft QUIC. A Use After Free could allow an unauthorized attacker to execute code over a network. This vulnerability has a CVSS base score of 9.8.  

Three vulnerabilities, CVE-2026-62896CVE-2026-62918 and CVE-2026-65667, affect Microsoft Teams. CVE-2026-62896 is an elevation of privilege vulnerability involving Improper Authentication that could allow an authorized attacker to elevate privileges over a network and has a CVSS base score of 9.6. CVE-2026-62918 involves Improper Verification of Cryptographic Signature that could allow an unauthorized attacker to perform spoofing over a network and has a CVSS base score of 7.5. CVE-2026-65667 is an elevation of privilege vulnerability involving Missing Authorization that could allow an unauthorized attacker to elevate privileges over a network and has a CVSS base score of 10.0.  

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:" 

CVE-2026-58650: Visual Studio Code Security Feature Bypass Vulnerability 

CVE-2026-63520: Microsoft SharePoint Server Remote Code Execution Vulnerability 

CVE-2026-59124: Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability 

CVE-2026-59133: Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vulnerability 

CVE-2026-59132: Windows TCP/IP Denial of Service Vulnerability 

CVE-2026-61348: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 

CVE-2026-61925: Windows Installer Elevation of Privilege Vulnerability 

CVE-2026-61930: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62688: Windows MIDI Service Module Elevation of Privileges Vulnerability 

CVE-2026-62696: Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability 

CVE-2026-62713: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 

CVE-2026-62712: Windows Win32k Elevation of Privilege Vulnerability 

CVE-2026-62735: Windows HTTP.sys Elevation of Privilege Vulnerability 

CVE-2026-62737: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62783: Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 

CVE-2026-62766: Windows Kerberos Elevation of Privilege Vulnerability 

CVE-2026-65788: Desktop Window Manager Elevation of Privilege Vulnerability 

CVE-2026-69278: Visual Studio Code Security Feature Bypass Vulnerability 

CVE-2026-70307: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 

CVE-2026-70335: GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability 

CVE-2026-66804: Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability 

CVE-2026-70355: Microsoft SharePoint Server Elevation of Privilege Vulnerability 

CVE-2026-61358: Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability 

CVE-2026-61929: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62698: Microsoft Digest Authentication Elevation of Privilege Vulnerability 

CVE-2026-62721: Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability 

CVE-2026-62741: Windows HTTP.sys Elevation of Privilege Vulnerability 

CVE-2026-62788: Windows Kernel Elevation of Privilege Vulnerability 

CVE-2026-62832: Windows User Profile Service Elevation of Privilege Vulnerability 

CVE-2026-62888: Windows DWM Core Library Elevation of Privilege Vulnerability 

CVE-2026-65775: Windows Win32k Elevation of Privilege Vulnerability 

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Secure Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org

Snort 2 rule coverage: 1:66902-1:66910, 1:66912-1:66923, 1:66929-1:66932, 1:66935-1:66948 

Snort 3 rule coverage: 1:66902, 1:301589-1:301607 

  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Cisco Talos
    Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to
     

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

14 de Julho de 2026, 17:27
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."

Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild.

CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileges locally.

CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An unauthorized attacker could exploit it to perform spoofing over a network.

The 57 "critical" entries break down by vulnerability type as follows: 48 remote code execution (RCE), seven elevation of privilege (EoP), 1 spoofing and 1 security feature bypass vulnerability.

The 48 critical RCE vulnerabilities affect a range of Microsoft Windows services and applications, including Windows Media and Media Foundation, the Windows DHCP client and DHCP Server service, Microsoft Office, Word, Excel and PowerPoint, Windows GDI and GDI+, the DirectX Graphics Kernel, Microsoft SharePoint, Microsoft SQL Server, the Windows Reliable Multicast Transport Driver (RMCAST), Windows TCP/IP, the Windows Server Network driver, the Windows Print Spooler, the Windows Secure Socket Tunneling Protocol (SSTP), Windows Active Directory Domain Services, Microsoft Defender, Microsoft Copilot, Microsoft Message Queuing (MSMQ), the Remote Desktop Client, Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (on-premises), and the Minecraft Bedrock Dedicated Server.

Eleven of the critical RCE vulnerabilities are rated "more likely" to be exploited. CVE-2026-50370 and CVE-2026-50518 are heap-based buffer overflows in the Windows DHCP Server service, exploitable by an unauthorized attacker over an adjacent network and over a network, respectively. CVE-2026-54128 is a use-after-free in the Windows DHCP client that allows an unauthorized attacker to execute code locally. CVE-2026-50327 and CVE-2026-50655 are heap-based buffer overflows in Windows Media and Windows Media Foundation. CVE-2026-54992 is a heap-based buffer overflow in the Microsoft Message Queuing Queue Manager. CVE-2026-56188 is a race condition in the Windows Server Network driver, and CVE-2026-55010 is a heap-based buffer overflow in the Minecraft Bedrock Dedicated Server that an unauthorized attacker could exploit over a network. CVE-2026-50522 and CVE-2026-58644 are deserialization vulnerabilities in Microsoft SharePoint that allow an unauthorized attacker to execute code over a network. CVE-2026-55944 is a deserialization vulnerability in Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (on-premises) that allows an unauthorized attacker to execute code over a network.

The remaining critical RCE vulnerabilities are rated "less likely" or "unlikely" to be exploited, or were not assigned an exploitation-likelihood rating by Microsoft. Microsoft Office and its applications account for a large share: CVE-2026-50314, CVE-2026-50467, CVE-2026-55018, CVE-2026-55022, CVE-2026-55045, CVE-2026-55049, CVE-2026-55056, CVE-2026-55129 and CVE-2026-55140 are in Microsoft Office; CVE-2026-55033, CVE-2026-55127 and CVE-2026-55132 are in Microsoft Word; and CVE-2026-55043, CVE-2026-55120 and CVE-2026-55123 are in Microsoft PowerPoint. These are typically triggered by opening a specially crafted document.

The remaining critical RCE vulnerabilities affect Windows Media and Media Foundation (CVE-2026-56189, CVE-2026-57087, CVE-2026-57090, CVE-2026-57094 and CVE-2026-58542), the Windows DHCP Server service (CVE-2026-48564 and CVE-2026-56159), Windows GDI+ and GDI (CVE-2026-49796, CVE-2026-50380 and CVE-2026-54122), the DirectX Graphics Kernel (CVE-2026-50382), the Remote Desktop Client (CVE-2026-50474), Microsoft SQL Server (CVE-2026-54117 and CVE-2026-54118), the Windows Reliable Multicast Transport Driver (CVE-2026-54982 and CVE-2026-54995), Windows TCP/IP (CVE-2026-54999), the Windows Print Spooler (CVE-2026-58608), the Windows SSTP (CVE-2026-50694), Windows Active Directory Domain Services (CVE-2026-49164), Microsoft Defender (CVE-2026-55011 and CVE-2026-55012) and Microsoft Copilot (CVE-2026-48561).

The seven critical elevation of privilege vulnerabilities are CVE-2026-42982 and CVE-2026-50392 in Windows Secure Kernel Mode; CVE-2026-50444 in the Windows Server Update Service (WSUS); CVE-2026-50680 and CVE-2026-54127 in Windows Hyper-V; CVE-2026-54121 in Active Directory Certificate Services; and CVE-2026-57092 in Microsoft Windows VMSwitch.

The single critical spoofing vulnerability is CVE-2026-55008 in Microsoft Exchange Server, caused by a cross-site scripting condition. The single critical security feature bypass is CVE-2026-55040 in Microsoft SharePoint Server, caused by weak authentication. Both are rated "more likely" to be exploited.

Several of the critical entries above — including the Copilot, Azure Synapse, Azure OpenAI, Exchange Online and Entra items — affect Microsoft cloud services, for which Microsoft has not assigned an exploitation-likelihood rating.

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"

·       CVE-2026-49170: Windows StateRepository API Server file Elevation of Privilege Vulnerability

·       CVE-2026-49795: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-49798: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-49805: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50297: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50325: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50329: Microsoft DWM Core Library Elevation of Privilege Vulnerability

·       CVE-2026-50332: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50343: Microsoft Install Service Elevation of Privilege Vulnerability

·       CVE-2026-50351: Windows Audio Compression Manager (ACM) Elevation of Privilege Vulnerability

·       CVE-2026-50375: DirectX Graphics Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50387: Windows GDI Elevation of Privilege Vulnerability

·       CVE-2026-50390: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50423: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50433: Windows Media Elevation of Privilege Vulnerability

·       CVE-2026-50436: Windows Kernel Elevation of Privilege Vulnerability

·       CVE-2026-50454: Windows User Interface Core Elevation of Privilege Vulnerability

·       CVE-2026-50475: Windows Kernel Information Disclosure Vulnerability

·       CVE-2026-50476: Windows Network Connections Service Elevation of Privilege Vulnerability

·       CVE-2026-50489: Win32k Elevation of Privilege Vulnerability

·       CVE-2026-50509: Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability

·       CVE-2026-50667: Windows Common Log File System Driver Elevation of Privilege Vulnerability

·       CVE-2026-50688: Windows Win32k Elevation of Privilege Vulnerability

·       CVE-2026-54114: Windows Win32k Elevation of Privilege Vulnerability

·       CVE-2026-54986: Windows Win32k Elevation of Privilege Vulnerability

·       CVE-2026-57091: Windows File History Service Elevation of Privilege Vulnerability

·       CVE-2026-58531: Windows SMB Elevation of Privilege Vulnerability

·       CVE-2026-58536: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

·       CVE-2026-58596: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

·       CVE-2026-58631: Windows Admin Center (WAC) Remote Code Execution Vulnerability

·       CVE-2026-58633: Desktop Window Manager Elevation of Privilege Vulnerability

·       CVE-2026-58638: Windows Boot Loader Security Feature Bypass Vulnerability

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.

Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are: 1:66733 - 1:66743, 1:66745 - 1:66785, 1:66791 - 1:66793, 1:66800 - 1:66807

The following Snort 3 rules are also available: 1:301555 - 1:301579, 1:301581 - 1:301583

  • ✇Malwarebytes
  • July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days
    Just one month ago, June 2026 Patch Tuesday broke Microsoft’s previous record with 206 CVEs and three zero‑days. July now triples that count, reinforcing that the era of “small” Patch Tuesdays may be over as AI‑driven vulnerability discovery ramps up. The update includes 59 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. Two are known to b
     

July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days

15 de Julho de 2026, 09:21

Just one month ago, June 2026 Patch Tuesday broke Microsoft’s previous record with 206 CVEs and three zero‑days. July now triples that count, reinforcing that the era of “small” Patch Tuesdays may be over as AI‑driven vulnerability discovery ramps up.

The update includes 59 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. Two are known to be actively exploited by attackers.

How to apply patches and check if you’re protected

These updates fix security problems and keep your Windows PC protected. Here’s how to make sure you’re up to date:

1. Open Settings

  • Click the Start button, then open Settings.

2. Go to Windows Update

  • Select Windows Update (usually at the bottom of the menu on the left).

3. Check for updates

  • Click Check for updates. Windows will search for the latest security updates.
  • If you’ve enabled Get the latest updates as soon as they’re available under More options, you may be prompted to restart immediately. If so, restart your computer to complete the update. Otherwise, continue to the next step.
    Windows Update History for July 2026

4. Download and install

  • If updates are available, they’ll start downloading automatically. When they’re ready, click Install or Restart now if prompted. Your computer may need a restart to finish the update.

5. Double-check you’re up to date

  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set.
Windows is up to date

Technical details

Let’s look at the three zero-days.

First is a Windows BitLocker security feature bypass vulnerability, tracked as CVE-2026-50661. It is not known to be actively exploited. Microsoft describes it as:

“Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”

In other words, even if you’ve encrypted your machine with BitLocker, an attacker could exploit this vulnerability to access your data if they have physical access to your computer.

Next is the actively exploited CVE-2026-56155, an Active Directory Federation Services (ADFS) elevation of privilege (EoP) vulnerability. ADFS is a Microsoft software component that provides single sign-on (SSO) and federated access. It acts as a trust broker between an organization’s Active Directory and applications. An attacker who successfully exploited this vulnerability could gain administrator privileges. Reportedly, Microsoft discovered the vulnerability while investigating active attacks.

Last but not least is CVE-2026-56164, a Microsoft SharePoint Server elevation of privilege vulnerability. SharePoint Server is the on-premises version of Microsoft’s web-based collaboration and document management platform. A missing authentication check in Microsoft Office SharePoint could allow an attacker to elevate privileges over a network.

Both actively exploited vulnerabilities have been added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog, which sets patch deadlines for Federal Civilian Executive Branch (FCEB) agencies. CISA has also urged organizations using SharePoint Server to implement hardening measures after the latest exploitations.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities Chetan Raghuprasad
    Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”. Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client
     

Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

9 de Junho de 2026, 18:21
Microsoft Patch Tuesday for June 2026 — Snort rules and prominent vulnerabilities

Microsoft has released its monthly security update for June 2026, which includes 206 vulnerabilities affecting a range of products, including 32 that Microsoft marked as “critical”. 

Out of 32 "critical" entries, 28 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Windows Active Directory, Windows Kerberos Key Distribution Centre (KDC), Windows Graphics component, Windows Remote Desktop client, Windows Deployment Services (WDS), DHCP Client service, Windows Hyper-V, Windows Kernel and Media, Azure Kubernetes Service (AKS), Microsoft Office, Microsoft Outlook, Microsoft Word, Microsoft SQL server and Windows HTTP Protocol Stack. 

Talos highlights 4 critical vulnerabilities as Microsoft has determined that their exploitation is “more likely:” 

CVE-2026-42985 is a critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Remote Desktop Client which allows an unauthorized attacker to execute code over a network. 

CVE-2026-47291 is a critical Remote Code Execution Vulnerability due to Integer overflow or wraparound in Windows HTTP Protocol Stack (http.sys). An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to a targeted server utilizing the HTTP Protocol Stack (http.sys) to process packets. 

CVE-2026-44803 and CVE-2026-44812 are critical Remote Code Execution Vulnerability in the Windows Graphics component. This vulnerability is due to Integer overflow or wraparound in Windows Win32K – GRFX subsystem (graphics component). An unauthorized attacker, exploiting this vulnerability can execute malicious code locally. 

Talos highlights 23 critical vulnerabilities as Microsoft has determined that their exploitation is “less likely:” 

CVE-2026-42992CVE-2026-44799CVE-2026-44801CVE-2026-47289 and CVE-2026-48563 are critical Remote Code Execution Vulnerability due to Heap-based buffer overflow in Windows Remote Desktop Client allows an unauthorized attacker to execute code over a network. Successful exploitation of this vulnerability necessitates that an attacker takes additional steps to prepare the target environment before exploitation. In the case of a Remote Desktop connection, an attacker who controls a Remote Desktop Server could initiate a remote code execution (RCE) on the machine when a victim connects to the attacking server using the vulnerable Remote Desktop Client. 

CVE-2026-45607CVE-2026-45641 and CVE-2026-47652 are critical Remote Code Execution vulnerabilities in Windows Hyper-V that arise from Out-of-bounds reads, which enable an unauthorized attacker to execute code locally. This vulnerability necessitates that an authenticated attacker on a guest virtual machine (VM) sends specially crafted file operation requests to hardware resources within the VM which could result in remote code execution on the host server. 

CVE-2026-45657 is a critical use after free vulnerability in Windows Kernel which allows an unauthorized attacker to execute malicious code over a network. An attacker could exploit this vulnerability by sending specially crafted network traffic to a vulnerable Windows system. With the successful exploitation attempt, the malicious network packets could trigger a flaw in how the Windows kernel processes certain TCP/IP data, potentially allowing the attacker to run code with system-level privileges without needing to sign in or interact with a user. 

CVE-2026-48574 is a critical Remote Code Execution vulnerability in Windows Media due to Heap-based buffer overflow which allows an unauthorized attacker to execute the malicious code locally.  

CVE-2026-42987 is a critical Remote Code Execution vulnerability in Windows Deployment Services (WDS). This vulnerability is due to the use after free flaw in Windows Deployment Services and an unauthorized attacker, exploiting this vulnerability, can execute malicious code over a network.  

CVE-2026-44815 is a critical Remote Code Execution vulnerability due to the Stack-based buffer overflow in Windows DHCP Client which allows an unauthorized attacker to execute code over a network. An authenticated user could exploit this vulnerability by sending specially crafted network traffic to a server configured for use as a Dynamic Host Configuration Protocol (DHCP) Server. 

CVE-2026-45456CVE-2026-45458, and CVE-2026-47635 are critical Remote Code Execution vulnerabilities in Microsoft Outlook and Word, caused by the access of resources using an incompatible type ('type confusion') in Microsoft Office. The exploitation of these vulnerabilities allows an unauthorized attacker to execute malicious code locally. Microsoft states that the attack vector is the preview pane of Outlook (classic), and this vulnerability can be exploited when rendering emails in Outlook (classic), as the email rendering in Outlook (classic) utilizes Microsoft Word functionality, where this vulnerability exists. 

CVE-2026-45461CVE-2026-45463CVE-2026-45472 and CVE-2026-45474 are critical Use after free flaw in Microsoft office when exploited, allows an unauthorized attacker to execute malicious code locally. 

CVE-2026-45476 is a critical Elevation of Privilege vulnerability in Microsoft Azure Network Adapter. The vulnerability is due to use after free flaw in Linux MANA Driver. An attacker who already has control of the host environment could trigger the flaw in the guest driver that mishandles memory. This could allow the attacker to read sensitive information from the guest and potentially use that access to gain higher privileges within the guest system. 

CVE-2026-44810 is a critical Improper authentication flaw in Windows Cryptographic Services, when exploited, allows an unauthorized attacker to elevate privileges locally. Microsoft states that, to exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system. Additionally, an attacker could convince a local user to open a malicious file. The attacker would have to convince the user to click a link, typically by way of an enticement in an email or instant message and then convince them to open the specially crafted file. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. 

CVE-2026-47644 is a critical information disclosure vulnerability due to the Improper neutralization of special elements in output used by a downstream component('injection') in Copilot Chat (Microsoft Edge). Exploiting this vulnerability allows an unauthorized attacker to disclose information over a network. 

CVE-2026-26142 is a remote code execution vulnerability due to deserialization of untrusted data in Nuance Powerscribe. Exploiting this vulnerability could allow an attacker to execute code over a network. 

Talos also highlights 6 critical vulnerabilities as Microsoft has determined that these are unlikely exploited.  

CVE-2026-32193 is a critical Remote Code Execution Vulnerability in Azure Kubernetes Service (AKS) due to Improper limitation of a pathname to a restricted directory (path traversal). An exploitation of this vulnerability allows an authorized attacker to execute the malicious code locally.  Microsoft states that this vulnerability can be exploited by an attacker who can run an untrusted container configured with host Network could send specially crafted requests to a host level service that was not intended for unauthenticated access. This action could allow the attacker to break out of the container and gain control of the AKS worker node. 

CVE-2026-45648 is a critical Remote Code Execution Vulnerability in Windows Active Directory Domain services due to a Stack-based buffer overflow flaw in Active Directory Domain services. An authorized attacker who exploits this vulnerability could execute the malicious code over a network.  

CVE-2026-47288 is a critical Remote Code Execution Vulnerability in Windows Kerberos Key Distribution Center (KDC) due to the Integer overflow or wraparound in Windows Kerberos, when exploited, allows an authorized attacker to execute malicious code over an adjacent network. 

CVE-2026-47654 is a critical Remote Code Execution Vulnerability in Remote Desktop Client due to the Heap-based buffer overflow flaw which when exploited allows an unauthorized attacker to execute malicious code over a network. 

CVE-2026-33828 is a critical Elevation of Privilege Vulnerability in Windows Device Health Attestation (DHA). This vulnerability is due to the trust boundary violation in Windows Attestation which when exploited, allows an authorized attacker to elevate privileges locally. 

CVE-2026-45460 is a critical Information disclosure vulnerability in Microsoft Office due to a buffer over-read flaw which when exploited allows an unauthorized attacker to disclose information locally. 

Talos also shares few other critical vulnerabilities where Microsoft had mentioned that their exploitation status is unknown or not applicable.  

CVE-2026-48567 is a critical elevation of privilege vulnerability in Azure HorizonDB. This vulnerability arises from an authentication bypass through spoofing in Azure HorizonDB. An unauthorized attacker exploiting this vulnerability can elevate their privileges over a network. 

CVE-2026-48579 is a critical information disclosure vulnerability in Microsoft Exchange Online caused by improper authorization. An unauthorized attacker exploiting this vulnerability could disclose information over a network. 

CVE-2026-45497 and CVE-2026-42824 is a remote code execution vulnerability in Microsoft M365 copilot due to improper neutralization of special elements used in a command (‘command injection’). An unauthorized attacker exploiting this vulnerability could execute code over a network.  

CVE-2026-47655 is a critical information disclosure vulnerability in Microsoft Graph that allows an authorized attacker to expose sensitive information to an unauthorized actor over a network. 

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"   

  • CVE-2026-42905: Windows DWM Core Library Elevation of Privilege Vulnerability 
  • CVE-2026-42980: NT OS Kernel Elevation of Privilege Vulnerability 
  • CVE-2026-42986: Microsoft Graphics Component Elevation of Privilege Vulnerability 
  • CVE-2026-42989: Winlogon Elevation of Privilege Vulnerability 
  • CVE-2026-45481: Microsoft SharePoint Server Spoofing Vulnerability 
  • CVE-2026-45586: Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability 
  • CVE-2026-45658 and CVE-2026-50507: Windows BitLocker Security Feature Bypass Vulnerability 
  • CVE-2026-47634: Microsoft SharePoint Server Spoofing Vulnerability 
  • CVE-2026-49160: Windows HTTP Protocol Stack (http.sys) Denial of Service Vulnerability  

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.    

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.    

Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are: 66572-66577, 66581,66589,66590,66594,66595, 66601-66604 

The following Snort 3 rules are also available: 301523-301525, 301527-301529, 301531, 301532. 

  • ✇Malwarebytes
  • Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days
    This month’s Patch Tuesday fixes 206 security flaws in Microsoft software, making it the biggest Patch Tuesday release ever. The update includes 32 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. None are known to have been actively exploited by attackers. The huge number of fixed vulnerabilities makes this the largest Patch Tuesday sin
     

Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days

10 de Junho de 2026, 09:43

This month’s Patch Tuesday fixes 206 security flaws in Microsoft software, making it the biggest Patch Tuesday release ever.

The update includes 32 critical vulnerabilities, as well as three publicly disclosed zero-days. Microsoft classifies these as zero-days because information about the vulnerabilities became public before patches were available. None are known to have been actively exploited by attackers.

The huge number of fixed vulnerabilities makes this the largest Patch Tuesday since Microsoft launched the program in October 2003. The company introduced the monthly update schedule after the Blaster worm caused disruption in the early days of Windows.

How to apply patches and check if you’re protected

These updates fix security problems and keep your Windows PC protected. Here’s how to make sure you’re up to date:

1. Open Settings

  • Click the Start button (the Windows logo at the bottom left of your screen).
  • Click on Settings (it looks like a little gear).

2. Go to Windows Update

  • In the Settings window, select Windows Update (usually at the bottom of the menu on the left).

3. Check for updates

  • Click the button that says Check for updates.
  • Windows will search for the latest Patch Tuesday updates.
  • If you have selected to get the latest updates as soon as they’re available, you may see this under More options.
    In which case you may see a Restart required message. Restart your system and the update will complete.
    restart required
  • If not, continue with the steps below.

4. Download and install

  • If updates are found, they’ll start downloading automatically. Once complete, you’ll see a button that says Install or Restart now.
  • Click Install if needed and follow any prompts. Your computer will usually need a restart to finish the update. If it does, click Restart now.

5. Double-check you’re up to date

  • After restarting, go back to Windows Update and check again. If it says You’re up to date, you’re all set!
Windows up to date

Technical details

One publicly disclosed vulnerability is important to mention. This flaw in Windows BitLocker is tracked as CVE-2026-50507 (CVSS score: 6.8 out of 10) and its description states:

“a protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.”

BitLocker is a built-in Windows security feature that encrypts your entire hard drive, securing your data from unauthorized access if your device is lost or stolen. However, this vulnerability could allow an attacker with physical access to bypass BitLocker Device Encryption and gain access to encrypted data.

Another is CVE-2026-49160 (CVSS score: 7.5 out of 10) in HTTP.sys. This vulnerability can be exploited to launch a remote denial-of-service attack against major web servers using a technique called HTTP/2 Bomb.

The third to discuss is CVE-2026-45586 (CVSS score: 7.8 out of 10) in the Windows Collaborative Translation Framework (CTFMON). An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. These elevation of privilege (EoP) vulnerabilities are especially valuable to attackers because they can be combined with other flaws to gain full control of a compromised system.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

  • ✇Cisco Talos Blog
  • Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Jaeson Schultz
    By Jaeson Schultz Microsoft has released its monthly security update for May 2026, which includes 137 vulnerabilities affecting a range of products, including 31 that Microsoft marked as “critical”. In this month's release, Microsoft has not observed any of the included vulnerabilities being actively exploited in the wild. Out of 31 "critical" entries, 16 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Microsoft Office, Microsoft Word, Win
     

Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities

12 de Maio de 2026, 16:57
Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities

By Jaeson Schultz 

Microsoft has released its monthly security update for May 2026, which includes 137 vulnerabilities affecting a range of products, including 31 that Microsoft marked as “critical”. 

In this month's release, Microsoft has not observed any of the included vulnerabilities being actively exploited in the wild. Out of 31 "critical" entries, 16 are remote code execution (RCE) vulnerabilities in Microsoft Windows services and applications including Microsoft Office, Microsoft Word, Windows Native WiFi Miniport Driver, Azure, Office for Android, Microsoft Dynamics 365, Windows GDI, Microsoft SharePoint, Windows Graphics Component, Windows Netlogon, and Windows DNS Client. 

CVE-2026-32161 is a critical use after free vulnerability. Concurrent execution using a shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network. 

CVE-2026-33109 is a critical access control vulnerability in Azure Managed Instance for Apache Cassandra. Improper access control allows an authorized attacker to execute code over a network.

CVE-2026-33844 is a critical input validation vulnerability in Azure Managed Instance for Apache Cassandra. Improper input validation allows an authorized attacker to execute code over a network.

CVE-2026-35421 is a critical heap-based buffer overflow vulnerability in Windows GDI that allows an unauthorized attacker to execute code locally. For this vulnerability to be exploited, a user would need to open or otherwise process a specially crafted Enhanced Metafile (EMF) file using Microsoft Paint. This action is necessary to trigger the affected graphics functionality in the Windows component. 

CVE-2026-40358 is a critical use after free vulnerability in Microsoft Office which allows an unauthorized attacker to execute code locally. 

CVE-2026-40361 is a critical use after free vulnerability in Microsoft Word that allows an unauthorized attacker to execute code locally. 

CVE-2026-40363 is a critical heap-based buffer overflow in Microsoft Office which allows an unauthorized attacker to execute code locally. 

CVE-2026-40364 is a critical heap-based buffer overflow vulnerability. Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. 

CVE-2026-40365 is a critical vulnerability affecting Microsoft SharePoint. Insufficient granularity of access control allows an authorized attacker to execute code over a network. In a network-based attack, an authenticated attacker, as at least a Site Owner, could write arbitrary code to inject and execute code remotely on the SharePoint Server. 

CVE-2026-40366 is a critical use after free vulnerability in Microsoft Word which allows an unauthorized attacker to execute code locally. 

CVE-2026-40367 is a critical vulnerability affecting Microsoft Word. An untrusted pointer dereference may allow an unauthorized attacker to execute code locally. 

CVE-2026-40403 is a critical heap-based buffer overflow vulnerability in Windows Win32K – GRFX that allows an authorized attacker to execute code locally. This vulnerability could lead to a contained execution environment escape. In the case of a Remote Desktop connection, an attacker with control of a Remote Desktop Server could trigger a remote code execution (RCE) on the machine when a victim connects to the attacking server with a vulnerable Remote Desktop Client. 

CVE-2026-41089 is a critical stack-based buffer overflow in Windows Netlogon that allows an unauthorized attacker to execute code over a network. An attacker could send a specially crafted network request to a Windows server that is acting as a domain controller. If successful, this could cause the Netlogon service to improperly handle the request, potentially allowing the attacker to run code on the affected system without needing to sign in or have prior access. 

CVE-2026-41096 is a critical heap-based overflow vulnerability in Windows DNS Client. An attacker could exploit this vulnerability by sending a specially crafted DNS response to a vulnerable Windows system, causing the DNS Client to incorrectly process the response and corrupt memory. In certain configurations, this could allow the attacker to run code remotely on the affected system without authentication. 

CVE-2026-42831 is a critical heap-based buffer overflow vulnerability in Office for Android that allows an unauthorized attacker to execute code locally. An attacker must send a user a malicious Office file and convince them to open it. 

CVE-2026-42898 is a critical code injection vulnerability in Microsoft Dynamics 365 (on-premises). Improper control of generation of code ('code injection') allows an authorized attacker to execute code over a network. An attacker with the required permissions could modify the saved state of a process session in Dynamics CRM and trigger the system to process that data, which could result in the server unintentionally executing malicious code.

Talos would also like to highlight the following "important" vulnerabilities as Microsoft has determined that their exploitation is "more likely:"   

  • CVE-2026-33835: Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 
  • CVE-2026-33837: Windows TCP/IP Local Elevation of Privilege Vulnerability 
  • CVE-2026-33840: Win32k Elevation of Privilege Vulnerability 
  • CVE-2026-33841: Windows Kernel Elevation of Privilege Vulnerability 
  • CVE-2026-35416: Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 
  • CVE-2026-35417: Windows Win32k Elevation of Privilege Vulnerability 
  • CVE-2026-40369: Windows Kernel Elevation of Privilege Vulnerability 
  • CVE-2026-40397: Windows Common Log File System Driver Elevation of Privilege Vulnerability 
  • CVE-2026-40398: Windows Remote Desktop Services Elevation of Privilege Vulnerability 

A complete list of all the other vulnerabilities Microsoft disclosed this month is available on its update page.    

In response to these vulnerability disclosures, Talos is releasing a new Snort ruleset that detects attempts to exploit some of them. Please note that additional rules may be released at a future date, and current rules are subject to change pending additional information. Cisco Security Firewall customers should use the latest update to their ruleset by updating their SRU. Open-source Snort Subscriber Ruleset customers can stay up to date by downloading the latest rule pack available for purchase on Snort.org.    

Snort 2 rules included in this release that protect against the exploitation of many of these vulnerabilities are: 1:66438-1:66445, 1:66451-1:66460, and 1:66470-1:66476.  

The following Snort 3 rules are also available: 1:301494-1:301497, 1:301500-1:301506, 1:66472-1:66473, and 1:66476. 

❌
❌