ZeroHour

CVE-2026-49160

mass1

HTTP/2 Resource Exhaustion Denial-of-Service in Microsoft Windows and Windows Server

CVSS 3.1
7.5 high
EPSS
54%p99
Published
()
Modified
AI analysis

CVE-2026-49160 is an uncontrolled resource consumption flaw (CWE-400) in the HTTP/2 implementation on Windows, allowing an unauthenticated remote attacker to exhaust system resources by sending crafted HTTP/2 network traffic to a service that accepts HTTP/2 connections. Related reporting describes this as an 'HTTP/2 bomb' technique that can remotely deny service to HTTP/2-capable servers, including Microsoft IIS on Windows as well as other vendors' implementations (NGINX, Apache, Envoy, Cloudflare), though this CVE is scoped to Microsoft's Windows client and server products. A successful attack yields high-impact denial of service with no confidentiality or integrity loss, so any system on the affected versions running an HTTP/2-enabled service, especially an internet-exposed one, is at risk. Affected versions span Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. There is no known public proof-of-concept and the flaw is not yet in CISA KEV, but its EPSS of 53.8% (99th percentile) signals a better-than-even chance of exploitation within 30 days, and it ships in Microsoft's record 206-vulnerability June 2026 Patch Tuesday.

What to do: Apply Microsoft's June 2026 Patch Tuesday updates across all listed Windows 10/11 and Windows Server versions, prioritizing internet-facing servers with HTTP/2 enabled (such as IIS). As interim mitigation, consider disabling or restricting HTTP/2 on exposed endpoints or fronting affected services with rate-limiting reverse proxies/load balancers that cap connection and resource usage. Given the 53.8% EPSS, treat this as a likely near-term exploitation target and verify patch status even though no public PoC or KEV listing exists yet.

Affected
microsoft Windows 101607, 1809, 21H2, 22H2
microsoft Windows 1123H2, 24H2, 25H2, 26H1
microsoft Windows Server2016, 2019, 2022, 2025
Estimated exposure
masshundreds of millions of Windows devices (Windows 10/11 run on ~1.4B active devices; Windows Server in the millions) — Windows 10/11 are deployed on well over a billion devices and Windows Server on tens of millions of systems, but only hosts exposing HTTP/2-capable services (e.g., IIS) to untrusted networks face realistic remote DoS risk, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
Weakness
CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news