Junglewise Threat Intelligence

CVE-2026-49788: Microsoft Windows DoS in HTTP/2 resource allocation

CVE-2026-49788 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability in how Microsoft Windows handles HTTP/2 network traffic could allow an attacker to crash or slow down a system remotely. This type of attack, known as a Denial of Service, can disrupt business operations by making web services or connected servers unavailable to legitimate users. No special access or user interaction is required for an attacker to trigger this issue.

Technical details

A Denial of Service (DoS) vulnerability exists in the Microsoft Windows HTTP/2 stack due to improper resource management (CWE-770). The flaw stems from the allocation of resources without sufficient limits or throttling when processing HTTP/2 streams. A remote, unauthenticated attacker can exploit this by sending specially crafted HTTP/2 requests over the network, leading to resource exhaustion and a system hang or crash. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2016. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 All versions including Server Core

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft released security updates and advisory.

References

Related threats