July 11, 2026
- CVE-2026-47291 in Windows HTTP.sys allows kernel code execution or DoS through a 16-bit overflow in header parsing during TLS — triggerable with crafted HTTP/1.x requests carrying many headers over HTTPS. ZDI published the technical writeup. Zero Day Initiative · Vulnerabilities & Exploits
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat