CVE-2026-62750CWE-187

CVE-2026-62750

Medium · published August 11, 2026

CVSS v3.1
6.5
EPSS
1%
Percentile
45.2
In the wild
Unconfirmed
What it is

Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an adjacent network.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00574 · 45.2th percentile
Weakness
CWE-187 · Partial String Comparison
Published
2026-08-11T21:18Z
Affected products (24)
ProductVersionsFixed in
microsoft/windows_10_1607< 10.0.14393.941810.0.14393.9418
microsoft/windows_10_1607< 10.0.14393.941810.0.14393.9418
microsoft/windows_10_1809< 10.0.17763.911510.0.17763.9115
microsoft/windows_10_1809< 10.0.17763.911510.0.17763.9115
microsoft/windows_10_21h2< 10.0.19044.766310.0.19044.7663
microsoft/windows_10_21h2< 10.0.19044.766310.0.19044.7663
microsoft/windows_10_21h2< 10.0.19044.766310.0.19044.7663
microsoft/windows_10_22h2< 10.0.19045.766310.0.19045.7663
microsoft/windows_10_22h2< 10.0.19045.766310.0.19045.7663
microsoft/windows_10_22h2< 10.0.19045.766310.0.19045.7663
microsoft/windows_11_23h2< 10.0.22631.751710.0.22631.7517
microsoft/windows_11_23h2< 10.0.22631.751710.0.22631.7517
microsoft/windows_11_24h2< 10.0.26100.910610.0.26100.9106
microsoft/windows_11_24h2< 10.0.26100.910610.0.26100.9106
microsoft/windows_11_25h2< 10.0.26200.910610.0.26200.9106
microsoft/windows_11_25h2< 10.0.26200.910610.0.26200.9106
microsoft/windows_11_26h1< 10.0.28000.270410.0.28000.2704
microsoft/windows_11_26h1< 10.0.28000.270410.0.28000.2704
microsoft/windows_server_2012all versions
microsoft/windows_server_2012all versions
microsoft/windows_server_2016< 10.0.14393.941810.0.14393.9418
microsoft/windows_server_2019< 10.0.17763.911510.0.17763.9115
microsoft/windows_server_2022< 10.0.20348.544010.0.20348.5440
microsoft/windows_server_2025< 10.0.26100.3322210.0.26100.33222
References (1)
EPSS history
Timeline
  • 11 AUG 17:04Z
    Windows HTTP Protocol Stack Tampering Vulnerability
    cvelistv5