Snort Subscriber Rules Update 2026-05-12

Research via Snort-sigs <[email protected]> Tue, 12 May 2026 19:28:55 +0000 (GMT)
Newsgroups gmane.comp.security.ids.snort.sigs
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
Talos is aware of vulnerabilities affecting products from Microsoft
Corporation.

Details:
Microsoft Vulnerability CVE-2026-33835:
A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66438 through 66439,
Snort 3: GID 1, SID 301494.

Microsoft Vulnerability CVE-2026-33837:
A coding deficiency exists in Microsoft Windows TCP/IP Local that may
lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66440 through 66441,
Snort 3: GID 1, SID 301495.

Microsoft Vulnerability CVE-2026-33840:
A coding deficiency exists in Microsoft Win32k that may lead to an
escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66442 through 66443,
Snort 3: GID 1, SID 301496.

Microsoft Vulnerability CVE-2026-33841:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66453 through 66454,
Snort 3: GID 1, SID 301501.

Microsoft Vulnerability CVE-2026-35416:
A coding deficiency exists in Microsoft Windows Ancillary Function
Driver for WinSock that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66455 through 66456,
Snort 3: GID 1, SID 301502.

Microsoft Vulnerability CVE-2026-35417:
A coding deficiency exists in Microsoft Windows Win32k that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66459 through 66460,
Snort 3: GID 1, SID 301504.

Microsoft Vulnerability CVE-2026-40361:
A coding deficiency exists in Microsoft Word that may lead to remote
code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66457 through 66458,
Snort 3: GID 1, SID 301503.

Microsoft Vulnerability CVE-2026-40364:
A coding deficiency exists in Microsoft Word that may lead to remote
code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66474 through 66475,
Snort 3: GID 1, SID 301506.

Microsoft Vulnerability CVE-2026-40369:
A coding deficiency exists in Microsoft Windows Kernel that may lead to
an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66444 through 66445,
Snort 3: GID 1, SID 301497.

Microsoft Vulnerability CVE-2026-40397:
A coding deficiency exists in Microsoft Windows Common Log File System
Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66470 through 66471,
Snort 3: GID 1, SID 301505.

Microsoft Vulnerability CVE-2026-40398:
A coding deficiency exists in Microsoft Windows Remote Desktop Services
that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66451 through 66452,
Snort 3: GID 1, SID 301500.

Microsoft Vulnerability CVE-2026-41089:
A coding deficiency exists in Microsoft Windows Netlogon that may lead
to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SID 66476,
Snort 3: GID 1, SID 66476.

Microsoft Vulnerability CVE-2026-41103:
A coding deficiency exists in Microsoft SSO Plugin for Jira &
Confluence that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 66472 through 66473,
Snort 3: GID 1, SIDs 66472 through 66473.

Talos has added and modified multiple rules in the browser-chrome,
browser-firefox, file-office, os-windows, policy-other and
server-webapp rule sets to provide coverage for emerging threats from
these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJqA392AAoJEHB/DbSAg2dxNh4P/j2/CDx+Ut9Si9KBgYZyQaDo
Tri7yOF5wsit7od/JjZ6QFqLdJYcEzKJTZIGH9HmHAi9nriJIn2Y8f36oxTP+3x7
9RAb/lEy1/ss0fVvnUO+czkb2bvsL9r/LvQBKh5Um41+1qc6IHRigw1tvfMk06Ps
CQMKKqtXgJgtJerS8MsmIH9DC6hKUOGGPrANID8gL51NKSlWxuiavckFCpQziIMX
4eIeF9DZHSwZtclnVVQrZ88x7tksAAeFliBUFYsvGEY0/hArTN5xfMqyn1DXDg0x
MoKVF9xdVfCMVBvK2C4zgbRel+zJEnBKgWdR4ojEuKzuqcRkuPnUHP2L6BFDwiDP
c7MWZQqbHtFxLYuH0dSvKBr5YKyy8sfhd+nFVUnPoWvP4G3SxieL60LgR2+CDbyK
KiK4jvqPMC7j2XdKgy9zd82fY5ix5NultRqCsLrjWKhkslDcDZI2uHXxqeYsQZ6U
IIMrty0nZ3gNjMRzNrNijeVSQUYhUBb0jyiN8/8c4SOrhSbje1MvUTNqujbRNU82
3GOyVgdVR0+lu5bZexlJbcVtJ8/vKrNBauwS4oUXsHOovsKPZpR+CCHCm01pdCbf
Rh9TxHqW5RAdxbEus8L9uk3ug1/Xdi90U7x5Y0kYAzHXeQNAre/TWg6YsWxFqd+H
S6ti9S+g7w/B1tXamhBf
=pibB
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
[email protected]
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!