THREAT INTELLIGENCE CYBERTTAKv3.0.3.0
LIVE FEED ACTIVE
← Back to Intel Feed
Secure route: /intel/ai-cve-2026-47291-remote-code-execution-in-the-windows-http-sys-driver-a92cab7c
criticalCVE-2026-472912026-07-10Vector: appsec

CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys Driver

A critical security vulnerability in the Windows HTTP.sys driver allows remote, unauthenticated attackers to potentially execute malicious code or crash systems by sending specifically crafted HTTP requests over TLS connections.

Decision Context

English Brief

A critical security vulnerability in the Windows HTTP.sys driver allows remote, unauthenticated attackers to potentially execute malicious code or crash systems by sending specifically crafted HTTP requests over TLS connections.

الموجز العربي

CVE-2026-47291: ثغرة تنفيذ تعليمات برمجية عن بُعد في برنامج تشغيل HTTP.sys في نظام ويندوز

ثغرة أمنية حرجة في برنامج تشغيل HTTP.sys في نظام ويندوز، تسمح للمهاجمين غير المصرح لهم بتنفيذ تعليمات برمجية ضارة أو التسبب في تعطل الأنظمة عبر إرسال طلبات HTTP معدة خصيصاً.

Affected Products
    Priority sectors
    GovernmentFinancial ServicesHealthcareCritical InfrastructureInformation Technology
    Immediate Actions
    1. 1Apply the official Microsoft security update for June 2026.
    2. 2To mitigate manually, set MaxRequestBytes registry key:
    3. 3Restart the HTTP service or the server to apply changes.