Security Risk Category

Race Condition Security Risks

Published vulnerability pages connected to Race Condition. Each page keeps one canonical URL and focused remediation guidance.

31 published Race Condition risks

Race Condition risks

Showing 1–31 of 31 published risks.

medium

CVE-2026-45712 mailpit vulnerability

Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine and (re-entrant) CSS-rewriting code path concurrently write to it under the lock. When the unsynchronized read coincides with a synchronized write, Go's runtime raises fatal error: concurrent map read and map write — a runtime.throw that is not recoverable by http.Server's handler-panic recover. The whole Mailpit process exits, taking the SMTP, POP3 and HTTP listeners down with it. Version 1.30.0 contains a patch.

CVE-2026-45712api-securitydenial-of-servicerace-condition

Updated Jul 21, 2026

medium

CVE-2026-55219 Paymenter vulnerability

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction. Because MySQL/MariaDB requires an enclosing transaction to enforce row-level locks, the guard is ineffective. Concurrent payment requests can exploit this race condition to read the same credit balance simultaneously, allowing users to pay multiple invoices using the same credit balance. In database systems like MySQL, a row lock only works inside a formal transaction; without one, the lock is completely ignored. Because there is no active lock, two payment requests sent at the exact same millisecond can look at the database at the same time. Both requests see the original credit balance, decide it is sufficient, and approve the payment. Because the payment processes successfully through ExtensionHelper::addPayment(), the application provisions the corresponding services or digital goods, resulting in direct financial or resource loss to the platform. This issue has been fixed in version 1.5.5.

CVE-2026-55219phprace-condition

Updated Jul 21, 2026

highEPSS 0.005

CVE-2026-56648 windows 10 1607 vulnerability

Time-of-check time-of-use (toctou) race condition in Windows Network File System allows an authorized attacker to elevate privileges over a network.

CVE-2026-56648windowsmemory-corruptionrace-condition

Updated Jul 19, 2026

mediumEPSS 0.007

CVE-2026-56649 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network.

CVE-2026-56649windowsmemory-corruptionrace-condition

Updated Jul 19, 2026

highEPSS 0.004

CVE-2026-42900 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Store allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-42900windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-44800 windows 11 23h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

CVE-2026-44800windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-48572 windows 11 23h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

CVE-2026-48572windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-49802 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-49802windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-49803 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows AppX Deployment Service allows an authorized attacker to elevate privileges locally.

CVE-2026-49803windowsrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-49806 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-49806windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-49808 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-49808linuxwindowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50356 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Windows App Store allows an authorized attacker to elevate privileges locally.

CVE-2026-50356windowsmicrosoftrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50384 windows 10 1809 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Clip Service allows an authorized attacker to elevate privileges locally.

CVE-2026-50384windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

high

CVE-2026-50305 windows 11 24h2 vulnerability

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVE-2026-50305windowsmicrosoftmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50317 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Operating Systems allows an authorized attacker to elevate privileges locally.

CVE-2026-50317windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50321 windows 10 1607 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-50321windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-50322 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.

CVE-2026-50322windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

mediumEPSS 0.002

CVE-2026-58543 windows 11 24h2 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges with a physical attack.

CVE-2026-58543windowsmemory-corruptionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-58628 windows 10 1809 vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Wireless Networking allows an authorized attacker to elevate privileges locally.

CVE-2026-58628windowsrace-condition

Updated Jul 17, 2026

highEPSS 0.001

CVE-2026-48344 creative cloud desktop application vulnerability

Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.

CVE-2026-48344remote-code-executionrace-condition

Updated Jul 17, 2026

highEPSS 0.002

CVE-2026-54107 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54107windowsmicrosoftprivilege-escalationrace-condition

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54111 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Print Driver allows an authorized attacker to elevate privileges locally.

CVE-2026-54111windowsmicrosoftinformation-disclosurememory-corruption

Updated Jul 16, 2026

highEPSS 0.002

CVE-2026-54112 in Microsoft Windows

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-54112windowsmicrosoftmemory-corruptionprivilege-escalation

Updated Jul 16, 2026

mediumEPSS 0.002

CVE-2026-57029 in Junos OS Evolved

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthenticated attacker to cause a Denial-of-Service (DoS). When the reachability of an sFlow collector changes, the corresponding...

CVE-2026-57029network-securitydenial-of-servicerace-condition

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-57030 in Junos OS

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS)....

CVE-2026-57030network-securitydenial-of-servicerace-condition

Updated Jul 15, 2026

highEPSS 0.004

CVE-2026-55950 Erlang/OTP Vulnerability

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. A DTLS server listener uses a single shared dtls_packet_demux gen_server process to route incoming UDP datagrams to the correct connection handler. When a DTLS client reconnects rapidly from the same source address and port (sending multiple ClientHello messages in quick succession), a race condition in the demux's internal gb_trees key-value store causes a {key_exists, {old, Client}} crash, terminating the demux process. Because the demux is shared across all DTLS associations on that listener, its crash immediately kills every active DTLS session, not just the attacker's. The attack is pre-authentication: the attacker only needs to send UDP datagrams containing valid ClientHello messages from the same source IP and port before the intermediate DOWN monitor message is processed by the gen_server. No credentials, no completed handshake, and no special configuration are required, and the crash can be repeated indefinitely to create a persistent denial of service for all clients of that listener. This vulnerability is associated with program file lib/ssl/src/dtls_packet_demux.erl. This issue affects OTP from OTP 25.3 before 29.0.3, 28.5.0.3, and 27.3.4.14 corresponding to ssl from 10.9 before 11.7.3, 11.6.0.3, and 11.2.12.10.

CVE-2026-55950network-securitydenial-of-servicerace-condition

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-55945 edge chromium vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to disclose information locally.

CVE-2026-55945browsermicrosoftrace-condition

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-58299 edge chromium vulnerability

Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.

CVE-2026-58299browsermicrosoftrace-condition

Updated Jul 13, 2026

highEPSS 0.002

Google Chrome GetUserMedia Race Condition Sandbox Escape Vulnerability

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15119browserrace-condition

Updated Jul 10, 2026

mediumEPSS 0.001

CoreWCF Unix Domain Socket POSIX Identity Race Condition Vulnerability

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF UnixDomainSocket POSIX peer identity resolution uses non-reentrant getpwuid and getgrgid calls, allowing concurrent connections to attribute one connection's identity to another or crash the host process under contention. This issue is fixed in versions 1.8.1 and 1.9.1.

CVE-2026-54778dotnetwindowsrace-conditionunix-domain-sockets

Updated Jul 10, 2026

critical

XAPI varstored UEFI Variable TOCTOU Vulnerability

varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, there were insufficient compiler barriers, creating TOCTOU issues with data in the shared buffer. The exact vulnerable behaviour depends on the code generated by the compiler. In a build of varstored using default settings, the attacker can control an index used in a jump table.

CVE-2025-58151virtualizationrace-condition

Updated Jul 9, 2026