http.sys security

  1. CVE-2026-47291: Confirmed Windows HTTP.sys RCE—Patch Tuesday Priority Guide

    Microsoft disclosed CVE-2026-47291 on June 9, 2026, as a Windows HTTP.sys remote code execution vulnerability in the HTTP protocol stack, giving administrators a Patch Tuesday item that matters most on systems where Windows itself is listening for and processing HTTP traffic. This is not merely...