CVE-2026-50452
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attack
CVSS
7.0
High
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: Jul 14, 2026 · Last modified: Jul 15, 2026 · CWE-362 · CWE-416
0.3%EPSS · 30 days0.3%
2026-07-152026-07-20
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2024-300809.8 CRI98.6%
——30Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability15hCVE-2022-250908.1 HIG95.4%
——29Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.12dCVE-2025-217607.8 HIG94.7%
——28In the Linux kernel, the following vulnerability has been resolved:
ndisc: extend RCU protection in ndisc_send_skb()
ndisc_send_skb() can be called without RTNL or RCU held.
Acquire rcu_read_lock() earlier, so that we can use dev_net_rcu()
and avoid a potential UAF.7dCVE-2026-335267.5 HIG94.7%
——28Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.6dCVE-2026-327487.5 HIG94.7%
——28Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.6dCVE-2024-300897.8 HIG94.2%
——28Microsoft Streaming Service Elevation of Privilege Vulnerability15h