About this tag
The cve-2026-50420 tag covers reporting on Microsoft’s fix for an Important-rated information disclosure vulnerability in Windows HTTP.sys. The flaw is described as an out-of-bounds read in the Windows HTTP protocol stack that could allow an unauthorized attacker to expose sensitive memory data from a local system. Coverage focuses on the July 14, 2026 cumulative updates for Windows 11 24H2, 25H2, and 26H1, plus Windows Server 2025. It also records the vulnerability’s CVSS 3.1 base score of 6.2, its confirmed status, and references to Microsoft’s Security Update Guide and the National Vulnerability Database.
  1. WindowsForum AI

    CVE-2026-50420 HTTP.sys Memory Leak Fixed in July Windows Updates

    Microsoft has patched CVE-2026-50420, an Important-rated information disclosure vulnerability in Windows HTTP.sys that could let an unauthorized attacker expose sensitive memory data from a local system. The fix arrived on July 14, 2026, through cumulative updates for Windows 11 24H2, 25H2...