CVE-2026-49160
mass1HTTP/2 Resource Exhaustion Denial-of-Service in Microsoft Windows and Windows Server
CVE-2026-49160 is an uncontrolled resource consumption flaw (CWE-400) in the HTTP/2 implementation on Windows, allowing an unauthenticated remote attacker to exhaust system resources by sending crafted HTTP/2 network traffic to a service that accepts HTTP/2 connections. Related reporting describes this as an 'HTTP/2 bomb' technique that can remotely deny service to HTTP/2-capable servers, including Microsoft IIS on Windows as well as other vendors' implementations (NGINX, Apache, Envoy, Cloudflare), though this CVE is scoped to Microsoft's Windows client and server products. A successful attack yields high-impact denial of service with no confidentiality or integrity loss, so any system on the affected versions running an HTTP/2-enabled service, especially an internet-exposed one, is at risk. Affected versions span Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025. There is no known public proof-of-concept and the flaw is not yet in CISA KEV, but its EPSS of 53.8% (99th percentile) signals a better-than-even chance of exploitation within 30 days, and it ships in Microsoft's record 206-vulnerability June 2026 Patch Tuesday.
What to do: Apply Microsoft's June 2026 Patch Tuesday updates across all listed Windows 10/11 and Windows Server versions, prioritizing internet-facing servers with HTTP/2 enabled (such as IIS). As interim mitigation, consider disabling or restricting HTTP/2 on exposed endpoints or fronting affected services with rate-limiting reverse proxies/load balancers that cap connection and resource usage. Given the 53.8% EPSS, treat this as a likely near-term exploitation target and verify patch status even though no public PoC or KEV listing exists yet.
| microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| microsoft Windows Server | 2016, 2019, 2022, 2025 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019, windows server 2022, windows server 2025
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H