CVE-2026-47291
massUnauthenticated RCE via Integer Overflow in Windows HTTP.sys
CVE-2026-47291 is an integer overflow/wraparound flaw (CWE-190, leading to buffer overflow CWE-122) in HTTP.sys, the kernel-mode HTTP listener built into Windows. An unauthenticated attacker can trigger it by sending specially crafted network requests to any service that exposes an HTTP.sys endpoint, such as IIS-hosted websites or applications built on the Windows HTTP Server API/HttpListener. Successful exploitation grants remote code execution on the target host with no user interaction or privileges required. All listed Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server (2012, 2016, 2019, 2022) releases are affected. The flaw is not yet in CISA KEV and no public PoC exists, but its EPSS of 22.8% (98th percentile) indicates an elevated likelihood of exploitation within the next 30 days; patches shipped in Microsoft's June 2026 Patch Tuesday release (206 fixes total).
What to do: Apply the June 2026 Microsoft security updates for every affected Windows release, prioritizing internet-facing servers running IIS or other HTTP.sys-based services. As an interim mitigation, restrict untrusted network access to ports served by HTTP.sys. Identify hosts with active HTTP.sys listeners (e.g., via 'netsh http show servicestate' or reviewing web-server exposure) and monitor for a public PoC or CISA KEV addition given the elevated EPSS.
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 10 | 22H2 |
| microsoft Windows 11 | 23H2 |
| microsoft Windows 11 | 24H2 |
| microsoft Windows 11 | 25H2 |
| microsoft Windows 11 | 26H1 |
| microsoft Windows Server 2012 | 2012 |
| microsoft Windows Server 2016 | 2016 |
| microsoft Windows Server 2019 | 2019 |
| microsoft Windows Server 2022 | 2022 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-122, CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H