CVE-2026-47291, a remote code execution vulnerability in HTTP.sys, is the top priority. It carries a CVSS score of 9.8, targets unauthenticated attackers over the HTTP protocol stack, and is rated by Microsoft as 'exploitation more likely.' Three separate researcher acknowledgements add further urgency.