Vulnerability record · CVE-2026-49160 · published 9 June 2026
CVE-2026-49160: Windows HTTP/2 resource consumption denial of service
Microsoft · Windows 10 1607
Windows HTTP/2 handling allows uncontrolled resource consumption (CWE-400), letting an unauthenticated remote attacker exhaust resources and deny service. The flaw affects a broad set of Windows 10, Windows 11 and Windows Server releases, so any internet- or network-exposed HTTP/2 endpoint on those platforms is a candidate target.
Description
Uncontrolled resource consumption in HTTP/2 allows an unauthorized attacker to deny service over a network.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityNetwork-reachable, unauthenticated availability impact across many widely deployed Windows versions, with high EPSS despite no KEV listing or known exploit.
What it is
Windows HTTP/2 handling allows uncontrolled resource consumption (CWE-400), letting an unauthenticated remote attacker exhaust resources and deny service. The flaw affects a broad set of Windows 10, Windows 11 and Windows Server releases, so any internet- or network-exposed HTTP/2 endpoint on those platforms is a candidate target.
Impact
An attacker can degrade or take down HTTP/2 service availability on the affected host; there is no confidentiality or integrity impact per the CVSS vector, only availability loss.
Attack surface
Reached over the network via HTTP/2 traffic (AV:N, PR:N, UI:N), so no authentication or user interaction is required. Any service on the affected Windows versions that accepts HTTP/2 connections is in scope.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is high at roughly 0.54 (99th percentile), indicating elevated near-term exploitation likelihood.
What to do
- Apply the Microsoft update for CVE-2026-49160 across all affected Windows 10, Windows 11 and Windows Server versions as the primary fix.
- Where patching is delayed, restrict or rate-limit HTTP/2 traffic at the edge and disable HTTP/2 on services that do not require it.
- Monitor connection and memory/CPU consumption on HTTP/2 listeners and cap concurrent streams or connections per client.
- Prioritize internet-facing and shared Windows Server hosts for patching before internal workstations.
Detection
- Alert on sustained spikes in concurrent HTTP/2 connections, streams or memory/CPU on Windows HTTP/2 listeners.
- Baseline normal HTTP/2 request and connection rates per host and flag deviations consistent with resource exhaustion.
- Correlate Windows event and IIS/HTTP.sys logs for repeated connection resets or service unavailability on affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49160 | Vendor Advisory |
Track CVE-2026-49160 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-49160), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.