Junglewise Threat Intelligence

CVE-2026-49160: Microsoft Windows denial of service in HTTP/2

CVE-2026-49160 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft's implementation of the HTTP/2 protocol could allow an attacker to crash or slow down a web server. This protocol is used to deliver websites and web services to users. An exploit would result in a denial of service, making websites or applications unavailable to customers and employees.

Technical details

A denial of service vulnerability exists in Microsoft's HTTP/2 stack due to uncontrolled resource consumption (CWE-400). An unauthenticated, remote attacker can exploit this by sending specially crafted HTTP/2 requests that exhaust system resources. This is a network-based attack that requires no user interaction or special privileges. Successful exploitation results in the affected service becoming unresponsive or crashing. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References