Junglewise Threat Intelligence

CVE-2026-49787: Microsoft Windows HTTP.sys denial of service

CVE-2026-49787 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in the Windows HTTP protocol stack (HTTP.sys) allows an unauthorized attacker to crash or freeze a system over the network. HTTP.sys is a core component that handles web requests for Windows services and applications like IIS. An exploit could lead to a total denial of service, disrupting business operations and making hosted websites or services unavailable.

Technical details

A denial of service vulnerability exists in the Windows HTTP protocol stack (HTTP.sys) due to improper resource allocation (CWE-770). The flaw allows an unauthenticated, remote attacker to send specially crafted requests that exhaust system resources because the component fails to properly limit or throttle these allocations. This can lead to a system hang or crash (BSOD). The vulnerability is reachable over the network without user interaction. Microsoft has released security updates to address this issue across various versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 All versions including Server Core

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats