DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:12:51ZSOURCES: 14CRITICAL: 31
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Sampled credentials from the FortiBleed dataset and confirmed they are authentic. Many of… /// @MsftSecIntel CRITICAL — Tracking FortiBleed downstream activity. Buyers of the FortiGate credential sets are… /// @TalosSecurity CRITICAL — FortiBleed is just one piece of a broader IAB operation. The same Russian-speaking actor… /// @MalwareHunterTeam CRITICAL — The Gentlemen RaaS internal data leak (May 2026, ~16GB) confirmed operators actively… /// @CrowdStrike CRITICAL — Gentlemen RaaS affiliates are deploying GentleKiller variants that specifically target…
31Critical Threats
18Active CVEs
19IOCs Tracked
11New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-47291PUBLISHED: 2026-06-09
CRITICALCVE-2026-47291

Windows HTTP.sys Integer Overflow RCE (Exploitation More Likely)

VENDOR: Microsoft//PRODUCT: Windows HTTP Protocol Stack (HTTP.sys) — IIS, WinRM, and Windows HTTP Services
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

An integer overflow (CWE-190) in the Windows HTTP.sys kernel-mode driver allows a remote, unauthenticated attacker to execute arbitrary code on systems with a non-default MaxRequestBytes registry configuration by sending a specially crafted HTTP request. Microsoft rates this 'Exploitation More Likely' — a stronger signal than the co-disclosed Kernel RCE — making it a priority target for internet-facing IIS and WinRM servers. No public exploit exists yet, but a registry workaround (enforcing default MaxRequestBytes) is available as an interim control while patching.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSWindows 10, Windows 11, Windows Server 2016/2019/2022/2025 (all versions) using non-default MaxRequestBytes registry values; systems at default MaxRequestBytes are not affected; fixed in June 2026 Patch Tuesday
  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47291
  • https://www.zerodayinitiative.com/blog/2026/6/9/the-june-2026-security-update-review
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/
  • https://threat-modeling.com/microsoft-june-2026-patch-tuesday-critical-cves/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn