AuraTracer智迹闻
中文

EVENT DOSSIER

Windows HTTP.sys integer overflow vulnerability (CVE-2026-62735) security risk notice

2026-09-02 08:00 Cybersecurity 🔥 28.9 heat score
1sources
1days unfolding
28.9heat score
4mentions
SummaryAI generated

Microsoft has disclosed that the Windows HTTP.sys component contains an integer overflow vulnerability, designated as CVE-2026-62735. This vulnerability could be exploited to lead to remote code execution; a security risk notice has been issued.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
MicrosoftQianxinQianxin CERTWindows HTTP.sys

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Microsoft × Qianxin1Microsoft × Qianxin CERT1Microsoft × Windows HTT…1Qianxin × Qianxin CERT1Qianxin × Windows HTTP.…1Qianxin CERT × Windows …1

SignalsSIGNALS

Keyword heat
  • Qianxin1
  • Qianxin CERT1
  • Windows HTTP.sys1
  • Microsoft1

All reports (1)SOURCES

安全内参 zh 2026-09-02 08:00

Security Advisory on Integer Overflow Vulnerability in Windows HTTP.sys (CVE-2026-62735)

# Security risk notice for Windows HTTP.sys integer overflow vulnerability (CVE-2026-62735) ## Overview of the vulnerability | Item | Description | |------|------------| | Vulnerability name | Windows HTTP Sys integer overflow vulnerability | | Vulnerability ID | CVE-2026-62735 | | Vulnerability ID (QVD) | QVD-2026-51050 | | Publication date | 2026-08-11 | | Impact scale | Million-level | | CISSP rating | High risk | | CVSS score | 7.8 | | Threat type | Privilege escalation | | Exploitability | High | | POC status | Public | | Off-the-shelf exploit status | Not found | ## Description of the harm An attacker can exploit this vulnerability by constructing specially crafted HTTP response header data to trigger integer overflow…