Source status: Microsoft's MDASH campaign table includes CVE-2026-33096. The MSRC acknowledgment separately names Milad Nasr of Anthropic and Calif.io working with Claude, establishing shared direct attribution.
Summary
CVE-2026-33096 is a Windows HTTP.sys denial-of-service vulnerability shipped in Microsoft’s May 2026 Patch Tuesday release. Microsoft includes it in the 16-CVE MDASH cohort.
Shared attribution
The MSRC reporter line also credits Milad Nasr of Anthropic and Calif.io researchers working with Claude. This page preserves both discovery paths while the site-wide unique-CVE calculation counts the identifier once.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.