Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Microsoft patched CVE-2026-47291, a critical remote code execution vulnerability in the Windows HTTP.sys protocol stack. This flaw allows unauthenticated remote attackers to exploit an integer overflow during HTTP/1.x header parsing over TLS, potentially leading to kernel-level code execution or den...
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as remote code execution (RCE) vulnerabilities. The update included CVE-2026-47291,...
In June 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe's update included 11 bulletins covering 123 CVEs, with critical vulnerabilities in Adobe Campaign Classic and ColdFusion. Two CVEs in Campaign Classic (CVE-2026-48303, CVE-2026-47938) r...