Http/2 Bomb - Vulnerability

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
June 3, 2026
Last Seen
June 10, 2026

Http/2 Bomb is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 10 intelligence report mentions.

Http/2 Bomb is a vulnerability tracked across 2 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed June 3, 2026; most recent activity June 10, 2026.

Related Threat Clusters

  • Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed

    On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…

    57 articles · Updated June 9, 2026
  • New HTTP/2 Bomb DoS Attack Crashes Major Web Servers

    The HTTP/2 Bomb is a newly discovered denial-of-service (DoS) attack that targets default configurations of major web servers, including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare Pingora. This attack,…

    11 articles · Updated June 3, 2026

Recent Intelligence Reports

  • Microsoft Fixes 200 CVEs in June Patch Tuesday — Infosecurity-Magazine · June 10, 2026
  • Microsoft Patches Record 200 Vulnerabilities in June 2026 Patch Tuesday — Thecyberexpress · June 10, 2026
  • Patch Tuesday - June 2026 — Rapid7 · June 9, 2026
  • AI is making Patch Tuesday (kinda) fun again — Theregister · June 9, 2026
  • Microsoft Patches 200 Flaws Including Three Zero-Days — Aiweekly.Co · June 9, 2026
  • Microsoft June 2026 Patch Tuesday fixes 5 zero-days, 200 flaws — Bleepingcomputer · June 9, 2026
  • Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws — Bleepingcomputer · June 9, 2026
  • Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws — Bleepingcomputer · June 9, 2026

Frequently asked questions

What is Http/2 Bomb?

Http/2 Bomb is a vulnerability tracked by ThreatCluster, appearing in 2 threat clusters built from 10 intelligence report mentions.

Is Http/2 Bomb still active?

The most recent intelligence report mentioning Http/2 Bomb on ThreatCluster is dated June 10, 2026. Activity was first observed June 3, 2026, giving a tracked span from then to June 10, 2026.

What is Http/2 Bomb associated with?

Across ThreatCluster reporting, Http/2 Bomb most frequently co-occurs with Chaotic Eclipse, Nightmare Eclipse, Data Breach, DDoS, Denial of Service, among 12 tracked related entities.

What are the latest developments involving Http/2 Bomb?

The most significant recent cluster is “Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed” (57 articles · Updated June 9, 2026). Http/2 Bomb appears across 2 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on Http/2 Bomb?

Http/2 Bomb appears in 10 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown