CVE-2026-42991
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authoriz
CVSS
7.8
High
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: Jun 9, 2026 · Last modified: Jul 23, 2026 · CWE-362 · CWE-416
0.2%EPSS · 30 days0.2%
2026-07-062026-08-02
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-663157.5 HIG—
———Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.10hCVE-2026-628708.8 HIG—
———Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.10hCVE-2026-69244——
———AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response. An attacker controlled server, or possibly an accidental response, could trigger a DoS in the client. The vulnerable path was error message construction in aiohttp/_http_parser.pyx, where an llhttp error-position pointer was used to build a snippet for malformed chunked responses and malformed request or response bytes at the buffer end. This issue is fixed in version 3.14.3.13hCVE-2025-15630——
———A race
condition exists in the cloud-based Omada device adoption process when an
attacker may be able to interact with the adoption workflow before a legitimate
device completes registration, resulting in provisioning information being
delivered to an attacker.
Successful
exploitation may allow disclosure of provisioning information intended for a
legitimate device.15hCVE-2026-204736.0 MED—
——0In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.14hCVE-2026-673007.5 HIG25.5%
——8FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibilityRects, icon buffers). The parser frees those nested buffers after the callback returns, so the queued async message later dispatches stale pointers, potentially causing memory corruption or a client crash.17h