Skip to content

CVE-2026-47291

CVE

Threat entity extracted from intelligence sources

Frequency
11
occurrences
First Seen
June 9, 2026
Last Seen
July 11, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

Microsoft patched CVE-2026-47291, a critical remote code execution vulnerability in the Windows HTTP.sys protocol stack. This flaw allows unauthenticated remote attackers to exploit an integer overflow during HTTP/1.x header parsing over TLS, potentially leading to kernel-level code execution or den...

On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as remote code execution (RCE) vulnerabilities. The update included CVE-2026-47291,...

In June 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe's update included 11 bulletins covering 123 CVEs, with critical vulnerabilities in Adobe Campaign Classic and ColdFusion. Two CVEs in Campaign Classic (CVE-2026-48303, CVE-2026-47938) r...

Public Exploits

Checking GitHub for proof-of-concept code…