CVE-2026-54107
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker
CVSS
8.8
High
EPSS
0.2%
p5
KEV
—
Exploit Today
2
0-100
Published: Jul 14, 2026 · Last modified: Jul 15, 2026 · CWE-362
0.2%EPSS · 30 days0.2%
2026-07-152026-07-30
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-441025.3 MED11.2%
——3An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid firmware file. This will cause the file to remain accessible for a short period before it is deleted due to improper locking during the cleanup process.1dCVE-2026-16727—0.4%
——0Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement.
Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.18hCVE-2026-179996.5 MED5.9%
——2Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)1dCVE-2026-179937.0 HIG1.1%
——0Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)18hCVE-2026-179797.5 HIG6.8%
——2Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)18hCVE-2026-17855—4.3%
——1Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)1d