CVE-2026-42978
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authoriz
CVSS
7.8
Alto
EPSS
0.2%
p16
KEV
—
Exploit Today
5
0-100
Publicado: 9 jun 2026 · Última mod.: 23 jul 2026 · CWE-362 · CWE-416
0.2%EPSS · 30 días0.2%
2026-07-312026-08-27
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-667984.3 MED—
———Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.7hCVE-2026-586164.4 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.13hCVE-2026-82258——
———SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users' concurrent requests.16hCVE-2026-420079.1 CRÍ—
———An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the context of that process. Disable the Sieve editheader extension. Update to non-vulnerable version. No publicly available exploits are known.15hCVE-2026-19316——
——0A double-free vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to create a Denial of Service (DoS) condition in VPN processing by sending specially crafted network traffic.15hCVE-2026-77358——
——0cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33.0 through 0.50.0, the TLS-enabled WebSocket client frees the TLS session before closing the WebSocket that still uses it, producing a use-after-free. In WebSocketClient::shutdown_and_close the SSL object is freed and the pointer cleared, but the subsequent WebSocket close still sends a close frame through the SSL socket stream, which holds a raw copy of the now-dangling session pointer and reads from and writes to the freed memory. The same freed-then-used ordering is reachable through the client's destructor and its connect path, so ordinary teardown of a secure WebSocket connection triggers the defect. This issue is fixed in version 0.50.1.1d