securityonline.info 6/12/2026, 1:50:51 AM · external

HTTP.sys RCE bug CVE-2026-47291 puts Windows systems at risk

HTTP.sys RCE bug CVE-2026-47291 puts Windows systems at risk
Developing story vulnerability 3 articles tracked
Microsoft June 2026 Patch Tuesday addresses 208 vulnerabilities
CyberSIXT Evidence Panel
Primary Source msrc.microsoft.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical HTTP.sys RCE vulnerability (CVE-2026-47291) has been detected, posing serious risks to millions of users, with a CVSS score of 9.8. This vulnerability allows unauthorized code execution over networks due to an integer overflow error. Although no public exploits have been observed yet, future exploitation is deemed highly likely, prompting urgent action from system administrators. Users are advised to apply June 2026 security updates and modify the MaxRequestBytes registry value to ensure safety.

Detailed instructions for applying fixes and temporary mitigations have been provided, emphasizing the importance of prompt system updates to prevent potential attacks.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline