CWE-362— Concurrent Execution using Shared Resource with Improper Synchronization (Race Condition)
The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.— MITRE CWE catalog
2,663 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-362page 44 of 54
- CVE-2026-17999MEDIUMCVSS 6.5EG 6.52026-07-30
Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-18150MEDIUMCVSS 5.3EG 5.32026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition.
- CVE-2026-18151MEDIUMCVSS 4.2EG 4.22026-09-14
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.
- CVE-2026-18250MEDIUMCVSS 5.0EG 6.32026-08-12
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a race condition.
- CVE-2026-19139HIGHCVSS 7.4EG 7.42026-08-06
Race in CredentialProvider in Google Chrome on Windows prior to 151.0.7922.109 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
- CVE-2026-19506HIGHCVSS 8.1EG 8.12026-08-19
Race condition in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote attacker to gain unauthorized access via concurrent authentication requests that exploit shared authentication state.
- CVE-2026-19975LOWCVSS 3.1EG 3.12026-08-17
A weakness has been identified in Azuriom CMS up to 1.2.12. This issue affects the function transferMoney of the file app/Http/Controllers/ProfileController.php of the component Money Transfer Handler. This manipulation causes time-of-chec…
- CVE-2026-20617HIGHCVSS 7.0EG 7.02026-02-11
A race condition was addressed with improved state handling. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, tvOS 26.3, visionOS 26.3, watchOS 26.3. An app may be able to gain r…
- CVE-2026-20677CRITICALCVSS 9.0EG 9.02026-02-11
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut …
- CVE-2026-20808HIGHCVSS 7.0EG 7.02026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Printer Association Object allows an authorized attacker to elevate privileges locally.
- CVE-2026-20814HIGHCVSS 7.0EG 7.02026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-20815HIGHCVSS 7.0EG 7.02026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- CVE-2026-20826HIGHCVSS 7.0EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to elevate privileges locally.
- CVE-2026-20830HIGHCVSS 7.0EG 7.02026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- CVE-2026-20836HIGHCVSS 7.0EG 7.02026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-20844HIGHCVSS 7.4EG 7.42026-01-13
Use after free in Windows Clipboard Server allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-20848HIGHCVSS 7.5EG 7.52026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-20853HIGHCVSS 7.4EG 7.42026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows WalletService allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-20858HIGHCVSS 7.8EG 7.82026-01-13
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20861HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20866HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20867HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20869HIGHCVSS 7.0EG 7.02026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
- CVE-2026-20873HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20874HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20877HIGHCVSS 7.8EG 7.82026-01-13
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20918HIGHCVSS 7.8EG 7.82026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20919HIGHCVSS 7.5EG 7.52026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-20921HIGHCVSS 7.5EG 7.52026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-20924HIGHCVSS 7.8EG 7.82026-01-13
Use after free in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20926HIGHCVSS 7.5EG 7.52026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-20927MEDIUMCVSS 5.3EG 5.32026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network.
- CVE-2026-20930HIGHCVSS 7.8EG 7.82026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
- CVE-2026-20934HIGHCVSS 7.5EG 7.52026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.
- CVE-2026-21221HIGHCVSS 7.0EG 7.02026-01-13
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.
- CVE-2026-21231HIGHCVSS 7.8EG 7.82026-02-10
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- CVE-2026-21234HIGHCVSS 7.0EG 7.02026-02-10
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-21237HIGHCVSS 7.0EG 7.02026-02-10
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
- CVE-2026-21697HIGHCVSS 8.1EG 8.12026-01-07
axios4go is a Go HTTP client library. Prior to version 0.6.4, a race condition vulnerability exists in the shared HTTP client configuration. The global `defaultClient` is mutated during request execution without synchronization, directly m…
- CVE-2026-22548MEDIUMCVSS 5.9EG 5.92026-02-04
When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reac…
- CVE-2026-22701MEDIUMCVSS 5.3EG 5.32026-01-10
filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permiss…
- CVE-2026-22702MEDIUMCVSS 4.5EG 4.52026-01-10
virtualenv is a tool for creating isolated virtual python environments. Prior to version 20.36.1, TOCTOU (Time-of-Check-Time-of-Use) vulnerabilities in virtualenv allow local attackers to perform symlink-based attacks on directory creation…
- CVE-2026-22851MEDIUMCVSS 5.9EG 5.92026-01-14
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer…
- CVE-2026-22856HIGHCVSS 8.1EG 8.12026-01-14
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another read…
- CVE-2026-22986MEDIUMCVSS 4.7EG 4.72026-01-23
In the Linux kernel, the following vulnerability has been resolved: gpiolib: fix race condition for gdev->srcu If two drivers were calling gpiochip_add_data_with_key(), one may be traversing the srcu-protected list in gpio_name_to_desc()…
- CVE-2026-23004MEDIUMCVSS 4.7EG 4.72026-01-25
In the Linux kernel, the following vulnerability has been resolved: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() syzbot was able to crash the kernel in rt6_uncached_list_flush_dev() in an interesting way [1] Cras…
- CVE-2026-23071MEDIUMCVSS 4.7EG 4.72026-02-04
In the Linux kernel, the following vulnerability has been resolved: regmap: Fix race condition in hwspinlock irqsave routine Previously, the address of the shared member '&map->spinlock_flags' was passed directly to 'hwspin_lock_timeout_…
- CVE-2026-23110MEDIUMCVSS 4.7EG 4.72026-02-04
In the Linux kernel, the following vulnerability has been resolved: scsi: core: Wake up the error handler when final completions race against each other The fragile ordering between marking commands completed or failed so that the error …
- CVE-2026-23115MEDIUMCVSS 4.7EG 4.72026-02-14
In the Linux kernel, the following vulnerability has been resolved: serial: Fix not set tty->port race condition Revert commit bfc467db60b7 ("serial: remove redundant tty_port_link_device()") because the tty_port_link_device() is not red…
- CVE-2026-23118MEDIUMCVSS 4.7EG 4.72026-02-14
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix data-race warning and potential load/store tearing Fix the following: BUG: KCSAN: data-race in rxrpc_peer_keepalive_worker / rxrpc_send_data_packet …
Map vulnerabilities like CWE-362 to your infrastructure
EchelonGraph correlates every CVE — across CWE-362 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →