CVE-2026-47291 – HTTP.sys Microsoft Windows 10 Version 1607

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“A memory corruption weakness can turn network access into complete system compromise.”

Microsoft has patched CVE-2026-47291 in Windows 10 Version 1607. The vulnerability involves buffer and integer overflow conditions that could allow an attacker to corrupt memory and potentially execute arbitrary code on an affected system.

The CVSS score is 9.8, which is Critical severity. The potential for remote code execution makes this a high-impact risk for unpatched systems.

Key Details

Affected Product
Microsoft Windows 10 1607
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-122
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.