Snort mailing list archives

Snort Subscriber Rules Update 2026-09-08


From: Research via Snort-sigs <snort-sigs () lists snort org>
Date: Tue, 8 Sep 2026 21:20:25 +0000 (GMT)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2026-68846:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67029 through 67030,
Snort 3: GID 1, SID 301628.

Microsoft Vulnerability CVE-2026-68876:
A coding deficiency exists in Microsoft Windows Program Compatibility
Assistant Service that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67031 through 67032,
Snort 3: GID 1, SID 301629.

Microsoft Vulnerability CVE-2026-68884:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67036 through 67037,
Snort 3: GID 1, SID 301632.

Microsoft Vulnerability CVE-2026-69277:
A coding deficiency exists in Microsoft Local Security Authority (LSA)
Server that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67083 through 67084,
Snort 3: GID 1, SID 301655.

Microsoft Vulnerability CVE-2026-69301:
A coding deficiency exists in Microsoft Windows Win32k that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67038 through 67039,
Snort 3: GID 1, SID 301633.

Microsoft Vulnerability CVE-2026-69305:
A coding deficiency exists in Microsoft Windows Search Component that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67040 through 67041,
Snort 3: GID 1, SID 301634.

Microsoft Vulnerability CVE-2026-69337:
A coding deficiency exists in Microsoft Windows Registry that may lead
to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67055 through 67056,
Snort 3: GID 1, SID 301641.

Microsoft Vulnerability CVE-2026-69364:
A coding deficiency exists in Microsoft Windows Print Spooler
Components that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67042 through 67043,
Snort 3: GID 1, SID 301635.

Microsoft Vulnerability CVE-2026-69366:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67057 through 67058,
Snort 3: GID 1, SID 301642.

Microsoft Vulnerability CVE-2026-69385:
A coding deficiency exists in Microsoft Windows TCP/IP that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67044 through 67045,
Snort 3: GID 1, SID 301636.

Microsoft Vulnerability CVE-2026-69406:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an information disclosure.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67067 through 67068,
Snort 3: GID 1, SID 301647.

Microsoft Vulnerability CVE-2026-69451:
A coding deficiency exists in Microsoft Windows Management
Instrumentation that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67061 through 67062,
Snort 3: GID 1, SID 301644.

Microsoft Vulnerability CVE-2026-69466:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67063 through 67064,
Snort 3: GID 1, SID 301645.

Microsoft Vulnerability CVE-2026-69473:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67069 through 67070,
Snort 3: GID 1, SID 301648.

Microsoft Vulnerability CVE-2026-69478:
A coding deficiency exists in Microsoft Windows Device Association
Service that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67047 through 67048,
Snort 3: GID 1, SID 301637.

Microsoft Vulnerability CVE-2026-69498:
A coding deficiency exists in Microsoft Windows Win32k that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67065 through 67066,
Snort 3: GID 1, SID 301646.

Microsoft Vulnerability CVE-2026-69530:
A coding deficiency exists in Microsoft Windows Reliable Multicast
Transport Driver (RMCAST) that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67053 through 67054,
Snort 3: GID 1, SID 301640.

Microsoft Vulnerability CVE-2026-69541:
A coding deficiency exists in Microsoft Virtual Hard Disk (VHD)
Miniport Driver Elevation of Privilege Vulernability that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67011 through 67012,
Snort 3: GID 1, SID 301619.

Microsoft Vulnerability CVE-2026-69585:
A coding deficiency exists in Microsoft Windows Search Component that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67059 through 67060,
Snort 3: GID 1, SID 301643.

Microsoft Vulnerability CVE-2026-69600:
A coding deficiency exists in Microsoft Windows Search Component that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67013 through 67014,
Snort 3: GID 1, SID 301620.

Microsoft Vulnerability CVE-2026-69605:
A coding deficiency exists in Microsoft Install Service that may lead
to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67073 through 67074,
Snort 3: GID 1, SID 301650.

Microsoft Vulnerability CVE-2026-69714:
A coding deficiency exists in Microsoft Windows Device Association
Service that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67015 through 67016,
Snort 3: GID 1, SID 301621.

Microsoft Vulnerability CVE-2026-69723:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an information disclosure.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67017 through 67018,
Snort 3: GID 1, SID 301622.

Microsoft Vulnerability CVE-2026-69757:
A coding deficiency exists in Microsoft Windows TCP/IP that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67019 through 67020,
Snort 3: GID 1, SID 301623.

Microsoft Vulnerability CVE-2026-69779:
A coding deficiency exists in Microsoft Windows Win32k that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67021 through 67022,
Snort 3: GID 1, SID 301624.

Microsoft Vulnerability CVE-2026-69832:
A coding deficiency exists in Microsoft Win32k that may lead to an
information disclosure.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67023 through 67024,
Snort 3: GID 1, SID 301625.

Microsoft Vulnerability CVE-2026-69911:
A coding deficiency exists in Microsoft Windows Search Component that
may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67071 through 67072,
Snort 3: GID 1, SID 301649.

Microsoft Vulnerability CVE-2026-69921:
A coding deficiency exists in Microsoft Windows Print Spooler
Components that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67077 through 67078,
Snort 3: GID 1, SID 301652.

Microsoft Vulnerability CVE-2026-70289:
A coding deficiency exists in Microsoft Windows Win32k that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67075 through 67076,
Snort 3: GID 1, SID 301651.

Microsoft Vulnerability CVE-2026-70342:
A coding deficiency exists in Microsoft Windows Ancillary Function
Driver for WinSock that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67079 through 67080,
Snort 3: GID 1, SID 301653.

Microsoft Vulnerability CVE-2026-70583:
A coding deficiency exists in Microsoft Windows Core Messaging that may
lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67081 through 67082,
Snort 3: GID 1, SID 301654.

Microsoft Vulnerability CVE-2026-70585:
A coding deficiency exists in Microsoft Windows Services for NFS ONCRPC
XDR Driver that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SID 67046,
Snort 3: GID 1, SID 67046.

Microsoft Vulnerability CVE-2026-71340:
A coding deficiency exists in Microsoft Windows File History Service
that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67049 through 67050,
Snort 3: GID 1, SID 301638.

Microsoft Vulnerability CVE-2026-71343:
A coding deficiency exists in Microsoft Windows Remote Access
Connection Manager that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67051 through 67052,
Snort 3: GID 1, SID 301639.

Microsoft Vulnerability CVE-2026-77500:
A coding deficiency exists in Microsoft Windows Device Association
Service that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67025 through 67026,
Snort 3: GID 1, SID 301626.

Microsoft Vulnerability CVE-2026-80093:
A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 67027 through 67028,
Snort 3: GID 1, SID 301627.

Talos has added and modified multiple rules in the malware-other and
server-webapp rule sets to provide coverage for emerging threats from
these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJqoHwYAAoJEHB/DbSAg2dxY5EP/1MAT3QGdKIsCgopceY3PsFs
etqVSz8eUFXwt4MMGSRX8XVEGMlyG0OapwIlLZQYwefcbeC30H3eOQJdKIjGIQxS
GZoCw5nwBMzdxeEU8fa3eQv7fanvgejtN5QKLuATezKiDRSuCdTKsISXq+yzPlQ6
pIJnU6hpbe8PzNHKoBcu/EOaCHIh2f10DM34ilR4ZVRE/1DfpyMp2TrA03tgfuod
yGE04mExyus0Y1aGekMnRC41WQEPydclvKjEVPGwQGFZOV+9KdgRft3ki17p77tq
+YMQD+9qPxL12WuWoePPPfSGfphONMa9d/Y5tGu+bRl/GUwMw5CbYBjdmfA/oaok
fk2VrSEa94ufI5rGxjYMZvMckuC+u3WuMumgeGt2T2S4ukhogc/aQPe9wO25U5cL
dRPdAt8g02DV4FpPQy2Oq2F6+4YtZdupB/JmmzxfF9V6+lAwVwaUTzqMVwRNxmmJ
a+IMwlXSF3CQpNuPGlUmZ3Si4AxjT28TEb9ANIq95ZQWcPy9KbkKe/J7N1bivwUm
TAmR6M3cW1Gx+uptxRnrHyPWxFamidLHITV2D62bJzs4gMyYKA6m5q7R4mEBBXrZ
9CM6AvEPEs0OgzVzyXYGcWEZQKiNwQx9JaghNuxoR37guZ+TZZ8f4Qfk6qPPn43z
u8kspJadmf7XUVhyAsx5
=AcaA
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: