logo

Millions at Risk: 9.8 CVSS Remote Code Execution in HTTP.sys

ID: 99530de6-2f8f-5dd3-93c9-d4d8fabcfd11

STIX ID: report--99530de6-2f8f-5dd3-93c9-d4d8fabcfd11

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Do Son

...
...

This advisory warns of a critical HTTP.sys RCE (CVE-2026-47291, CVSS 9.8) caused by an integer overflow/wraparound that could allow remote code execution. Microsoft reports no public exploits yet but considers reliable exploit code likely; the report urges immediate installation of June 2026 security updates and offers a temporary mitigation by adjusting the MaxRequestBytes registry value (with restart) and instructions to revert after patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.