← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 10, 2026 · 14:00via Zero Day Initiative Blog

CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys

Brief

In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation of this vulnerability can result in a denial-of-service condition, or, in the worst case, code execution with kernel privileges.

The following is a portion of their write-up covering CVE-2026-47291, with a few minimal modifications. A remote code execution vulnerability exists in the HTTP Protocol Stack for Microsoft Internet Information Services implemented in HTTP. sys. The vulnerability is due to invalid validating incoming HTTP requests.

A remote, unauthenticated attacker can exploit this vulnerability by sending crafted HTTP packets to the target system.

Read more on Zero Day Initiative Blog