Millions at Risk: 9.8 CVSS Remote Code Execution in HTTP.sys
ID: 99530de6-2f8f-5dd3-93c9-d4d8fabcfd11
STIX ID: report--99530de6-2f8f-5dd3-93c9-d4d8fabcfd11
Feed Name: securityonline.info
Threat Score
This advisory warns of a critical HTTP.sys RCE (CVE-2026-47291, CVSS 9.8) caused by an integer overflow/wraparound that could allow remote code execution. Microsoft reports no public exploits yet but considers reliable exploit code likely; the report urges immediate installation of June 2026 security updates and offers a temporary mitigation by adjusting the MaxRequestBytes registry value (with restart) and instructions to revert after patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
