CVE-2026-49975 is a vulnerability tracked across 6 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed June 3, 2026; most recent activity July 20, 2026.
Slackware 15.0 released urgent updates for two significant vulnerabilities on June 3, 2026. The first addresses a stack-based buffer overflow in the net-tools package (CVE-2026-154) affecting network interface handling.…
Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows…
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
A vulnerability in nginx was discovered that allows remote attackers to cause excessive resource consumption through specially crafted HTTP/2 cookie headers, leading to denial of service (CVE-2026-49975). The initial…
The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack,…
Oracle has released advisories for multiple denial-of-service (DoS) vulnerabilities affecting mod_http2 in Oracle Linux 10. The vulnerabilities include CVE-2026-43951, CVE-2026-48913, and CVE-2026-49975, all published…