CWE-362
Two concurrent operations interleave, and the attacker exploits the window between them.
- 66
- vulnerabilities tracked
- 1
- critical
- 27 July 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-43693A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.NVD analysis in progress High CVSS 7 CVE-2026-43755A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.NVD analysis in progress High CVSS 7 CVE-2026-63756SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.Surrealdb High CVSS 8.1 CVE-2026-51082A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call "vncproxy" to hijack a VNC session that is established in parallel by a different user for a different VM. High CVSS 7.2 CVE-2026-58598Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 21h2 High CVSS 7 CVE-2026-53517Better Auth is an authentication and authorization library for TypeScript. From 1.4.8-beta.7 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint on the refresh_token grant performs a non-atomic read, validate, revoke, and mint sequence on the oauthRefreshToken row, allowing concurrent requests with the same parent refresh token to pass the revoked check and create forked refresh-token families; the vulnerable range also includes embedded better-auth plugin versions before 1.6.0. This issue is fixed in version 1.6.11.Better-auth Better-auth\/oauth-provider High CVSS 8.1 CVE-2026-53518Better Auth is an authentication and authorization library for TypeScript. From 1.6.0 until 1.6.11, the @better-auth/oauth-provider POST /oauth2/token endpoint for the authorization_code grant redeems a single-use authorization code through a non-atomic find-then-delete sequence, allowing two concurrent requests to pass the read step and mint independent access tokens, refresh tokens, and ID tokens; legacy /oauth2/token and /mcp/token paths in oidc-provider and mcp plugins share the same primitive. This issue is fixed in version 1.6.11.Better-auth Better-auth\/oauth-provider High CVSS 8.1 CVE-2026-42900Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.1 CVE-2026-44800Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 High CVSS 7.8 CVE-2026-48572Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 23h2 High CVSS 7 CVE-2026-49183Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-49784Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-49802Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-49803Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-49806Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-49808Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50305Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50317Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50321Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50322Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50345Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50348Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1809 High CVSS 8.1 CVE-2026-50356Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50361Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50369Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-50371Concurrent execution using shared resource with improper synchronization ('race condition') in Windows LUAFV allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50378Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50379Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 High CVSS 7.5 CVE-2026-50384Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50385Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 8.8 CVE-2026-50398Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 High CVSS 7.5 CVE-2026-50403Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50404Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50414Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network.Microsoft Windows 11 24h2 High CVSS 8.8 CVE-2026-50427Use after free in Content Delivery Manager allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50440Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Audio Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50450Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Wide Area Network Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50452Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1809 High CVSS 8.1 CVE-2026-50457Use after free in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-50458Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50460Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.Microsoft Windows 10 1809 High CVSS 8.1 CVE-2026-50503Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50667Concurrent execution using shared resource with improper synchronization ('race condition') in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50669Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-50672Use after free in Windows NTFS allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-50676Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-50677Use after free in Windows Media allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7.8 CVE-2026-50689Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-54107Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1607 High CVSS 7 CVE-2026-54111Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-54112Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7 CVE-2026-54125Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-54991Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-54996Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-54999Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over an adjacent network.Microsoft Windows 10 1607 High CVSS 8.8 CVE-2026-56188Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 CVE-2026-56649Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 8.1 CVE-2026-58526Use after free in Windows Storage allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-58527Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.Microsoft Windows 11 24h2 High CVSS 7 CVE-2026-58531Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-58608Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network.Microsoft Windows 10 1607 High CVSS 7.5 CVE-2026-58628Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.Microsoft Windows 10 1809 High CVSS 7.8 CVE-2026-15119Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)Google Chrome High CVSS 8.3 CVE-2026-56297FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to improper synchronization of channel_callback access. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service.Freerdp High CVSS 8.1 CVE-2026-5120A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from another user. High CVSS 8.1 CVE-2026-13882Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)Google Chrome Critical CVSS 9.6