CVE-2026-49975 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
8
occurrences
First Seen
June 3, 2026
Last Seen
July 20, 2026

CVE-2026-49975 is a vulnerability tracked across 6 threat clusters and 8 intelligence report mentions on ThreatCluster. First observed June 3, 2026; most recent activity July 20, 2026.

Related Threat Clusters

  • Slackware 15.0 Security Updates Address Critical Vulnerabilities

    Slackware 15.0 released urgent updates for two significant vulnerabilities on June 3, 2026. The first addresses a stack-based buffer overflow in the net-tools package (CVE-2026-154) affecting network interface handling.…

    17 articles · Updated June 3, 2026
  • Oracle Linux 9 Vulnerabilities Lead to Critical Security Advisories

    Oracle Linux 9 has issued two important advisories addressing critical vulnerabilities in the Apache HTTP Server. The first advisory (ELSA-2026-21391) details multiple CVEs, including CVE-2026-28780, which allows…

    4 articles · Updated June 25, 2026
  • Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed

    On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…

    57 articles · Updated June 9, 2026
  • Nginx Denial of Service Vulnerability and Regression Issues

    A vulnerability in nginx was discovered that allows remote attackers to cause excessive resource consumption through specially crafted HTTP/2 cookie headers, leading to denial of service (CVE-2026-49975). The initial…

    11 articles · Updated June 8, 2026
  • New HTTP/2 Bomb DoS Attack Crashes Major Web Servers

    The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack,…

    11 articles · Updated June 3, 2026
  • Oracle Linux 10 mod_http2 DoS Vulnerabilities Disclosed

    Oracle has released advisories for multiple denial-of-service (DoS) vulnerabilities affecting mod_http2 in Oracle Linux 10. The vulnerabilities include CVE-2026-43951, CVE-2026-48913, and CVE-2026-49975, all published…

    2 articles · Updated July 20, 2026

Recent Intelligence Reports

  • Oracle Linux 10 mod_http2 Important DoS Vulnerability ELSA-2026 — Linuxsecurity · July 20, 2026
  • Oracle Linux 10 mod_http2 Moderate DoS Advisory ELSA-2026 — Linuxsecurity · July 20, 2026
  • Oracle Linux 9 mod_http2 Important Remote DoS Advisory ELSA-2026 — Linuxsecurity · June 25, 2026
  • Patch Tuesday - June 2026 — Rapid7 · June 9, 2026
  • Ubuntu 26.04 LTS Nginx Critical Denial Of Service Regression Vuln 8398 — Linuxsecurity · June 9, 2026
  • USN-8398-2: nginx regression — Ubuntu · June 9, 2026
  • Slackware 15.0 httpd Important DoS Fix for CVE-2026-49975 2026-154 — Linuxsecurity · June 3, 2026
  • New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute — Bleepingcomputer · June 3, 2026

CVSS v3.1 Breakdown