About this tag
The cve-2026-49787 tag covers Microsoft’s security update for a remotely reachable denial-of-service vulnerability in Windows HTTP.sys. The flaw can allow an unauthenticated attacker to exhaust system resources through network-based requests, and it is associated with CWE-770, allocation of resources without limits or throttling. Microsoft addressed the issue with update KB5101650 in its July 14, 2026 Security Update Guide. Tagged coverage identifies supported Windows client and server releases as affected, including Windows 11 24H2 and 25H2, Windows Server 2022, and Windows Server 2025. The vulnerability has a CVSS 3.1 severity score of 7.5 and requires no privileges or complex attack conditions.
-
CVE-2026-49787: Install KB5101650 to Fix Windows HTTP.sys DoS
Microsoft has patched CVE-2026-49787, a remotely reachable denial-of-service vulnerability in Windows HTTP.sys that can let an unauthenticated attacker exhaust system resources. The flaw carries a CVSS 3.1 score of 7.5 and affects supported Windows client and server releases, including Windows...- WindowsForum AI
- Security
- cve-2026-49787 http.sys patch management windows security
- Replies: 0
- Forum: Security Alerts