<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Race Condition (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/race.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/race-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Race Condition (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:28 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-40290 – OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40290</guid>
    <pubDate>Wed, 03 Jun 2026 18:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40290</strong></p>
  <p>OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior to 4.11.0, a user-after-free (UAF) race condition exists in the shared memory teardown logic of FF-A  within OP-TEE SPMC/SP flows. This only applies when OP-TEE is configured as an SPMC for S-EL0 SPs,…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41259 – SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41259</guid>
    <pubDate>Wed, 03 Jun 2026 13:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41259</strong></p>
  <p>SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49134 – CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49134</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49134</strong></p>
  <p>CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in temporary file handling. The installer creates a temporary file with mktemp, writes a privileged shell payload into it, and executes it with administrator privileges via bash, allowing a same-user local proc…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-377</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-47331 – Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47331</guid>
    <pubDate>Thu, 28 May 2026 19:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47331</strong></p>
  <p>Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46215 – In the Linux kernel, the following vulnerability has been resolved:

drm: Set ol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46215</guid>
    <pubDate>Thu, 28 May 2026 10:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46215</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  drm: Set old handle to NULL before prime swap in change_handle  There was a potential race condition in change_handle. The ioctl briefly had a single object with two idr entries; a concurrent gem_close could delete the object and remove one of the handles while leaving the other one dangling, which could subsequently be derefere…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46058 – In the Linux kernel, the following vulnerability has been resolved:

media: amph...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46058</guid>
    <pubDate>Wed, 27 May 2026 14:17:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46058</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: amphion: Fix race between m2m job_abort and device_run  Fix kernel panic caused by race condition where v4l2_m2m_ctx_release() frees m2m_ctx while v4l2_m2m_try_run() is about to call device_run with the same context.  Race sequence:   v4l2_m2m_try_run():           v4l2_m2m_ctx_release():     lock/unlock…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46011 – In the Linux kernel, the following vulnerability has been resolved:

media: mtk-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46011</guid>
    <pubDate>Wed, 27 May 2026 14:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46011</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: mtk-jpeg: fix use-after-free in release path due to uncancelled work  The mtk_jpeg_release() function frees the context structure (ctx) without first cancelling any pending or running work in ctx->jpeg_work. This creates a race window where the workqueue callback may still be accessing the context memory after it has been…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45945 – In the Linux kernel, the following vulnerability has been resolved:

iommu/vt-d:...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45945</guid>
    <pubDate>Wed, 27 May 2026 14:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45945</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  iommu/vt-d: Fix race condition during PASID entry replacement  The Intel VT-d PASID table entry is 512 bits (64 bytes). When replacing an active PASID entry (e.g., during domain replacement), the current implementation calculates a new entry on the stack and copies it to the table using a single structure assignment.          st…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45942 – In the Linux kernel, the following vulnerability has been resolved:

ext4: fix e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45942</guid>
    <pubDate>Wed, 27 May 2026 14:17:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45942</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ext4: fix e4b bitmap inconsistency reports  A bitmap inconsistency issue was observed during stress tests under mixed huge-page workloads. Ext4 reported multiple e4b bitmap check failures like:  ext4_mb_complex_scan_group:2508: group 350, 8179 free clusters as per group info. But got 8192 blocks  Analysis and experimentation con…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-45910 – In the Linux kernel, the following vulnerability has been resolved:

RDMA/rxe: F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45910</guid>
    <pubDate>Wed, 27 May 2026 14:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-45910</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  RDMA/rxe: Fix race condition in QP timer handlers  I encontered the following warning:  WARNING: drivers/infiniband/sw/rxe/rxe_task.c:249 at rxe_sched_task+0x1c8/0x238 [rdma_rxe], CPU#0: swapper/0/0 ...   libsha1 [last unloaded: ip6_udp_tunnel]  CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Tainted: G         C          6.19.0-rc5-64k-v8…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46284 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46284</guid>
    <pubDate>Tue, 26 May 2026 22:16:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46284</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to gain root privileges.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44469 – The affected product extracts installation files to a temporary directory with i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44469</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44469</guid>
    <pubDate>Tue, 26 May 2026 08:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44469</strong></p>
  <p>The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44469">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-46727 – An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46727</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46727</guid>
    <pubDate>Fri, 22 May 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46727</strong></p>
  <p>An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remote attacker who can delay DNS responses near the user-specified timeout to crash a Ruby process that calls Addrinfo.getaddrinfo(..., timeout:) or Socket.tcp(..., resolv_timeout:). Memory-corruption-bas…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46727">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5947 – Undefined behavior may result due to a race condition leading to a use-after-fre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5947</guid>
    <pubDate>Wed, 20 May 2026 13:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5947</strong></p>
  <p>Undefined behavior may result due to a race condition leading to a use-after-free violation.  If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature.  If, during that validation, the "recursive-clients" limit is reached (as would occur during a query flood), and that same DNS message is discarded per the limit, there is a brief window of time while…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29518 – Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29518</guid>
    <pubDate>Wed, 20 May 2026 13:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29518</strong></p>
  <p>Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that allows attackers to redirect file writes outside intended directories by replacing parent directory components with symbolic links. Attackers with write access to a module path can exploit this race condition to create or overwrite arbitrary files, potentially modifying sensitiv…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42099 – Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_int...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42099</guid>
    <pubDate>Tue, 19 May 2026 14:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42099</strong></p>
  <p>Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The application downloads the properties of the object pointed by guid parameter and saves loaded content in current location (__DIR__) under the specified name. An attacker with repository access can control both the filename and file contents, allowing the creation of a malicious PHP fil…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40399 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40399</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40399</guid>
    <pubDate>Tue, 12 May 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40399</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40399">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34351 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34351</guid>
    <pubDate>Tue, 12 May 2026 18:17:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34351</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34342 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34342</guid>
    <pubDate>Tue, 12 May 2026 18:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34342</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34334 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34334</guid>
    <pubDate>Tue, 12 May 2026 18:17:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34334</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34331 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34331</guid>
    <pubDate>Tue, 12 May 2026 18:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34331</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34330 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34330</guid>
    <pubDate>Tue, 12 May 2026 18:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34330</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33840 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33840</guid>
    <pubDate>Tue, 12 May 2026 18:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33840</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33839 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33839</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33839</guid>
    <pubDate>Tue, 12 May 2026 18:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33839</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33839">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32161 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32161</guid>
    <pubDate>Tue, 12 May 2026 18:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32161</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Native WiFi Miniport Driver allows an unauthorized attacker to execute code over an adjacent network.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7432 – A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7432</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7432</guid>
    <pubDate>Tue, 12 May 2026 15:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7432</strong></p>
  <p>A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7432">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35227 – An unauthenticated remote attacker may exhaust all available TCP connections in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35227</guid>
    <pubDate>Tue, 12 May 2026 08:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35227</strong></p>
  <p>An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-772</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28986 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28986</guid>
    <pubDate>Mon, 11 May 2026 21:18:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28986</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected system termination.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28924 – A race condition was addressed with improved handling of symbolic links. This is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28924</guid>
    <pubDate>Mon, 11 May 2026 21:18:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28924</strong></p>
  <p>A race condition was addressed with improved handling of symbolic links. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access Contacts without user consent.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43447 – In the Linux kernel, the following vulnerability has been resolved:

iavf: fix P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43447</guid>
    <pubDate>Fri, 08 May 2026 15:16:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43447</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  iavf: fix PTP use-after-free during reset  Commit 7c01dbfc8a1c5f ("iavf: periodically cache PHC time") introduced a worker to cache PHC time, but failed to stop it during reset or disable.  This creates a race condition where `iavf_reset_task()` or `iavf_disable_vf()` free adapter resources (AQ) while the worker is still running…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43408 – In the Linux kernel, the following vulnerability has been resolved:

ceph: add a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43408</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43408</guid>
    <pubDate>Fri, 08 May 2026 15:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43408</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ceph: add a bunch of missing ceph_path_info initializers  ceph_mdsc_build_path() must be called with a zero-initialized ceph_path_info parameter, or else the following ceph_mdsc_free_path_info() may crash.  Example crash (on Linux 6.18.12):    virt_to_cache: Object is not a Slab page!   WARNING: CPU: 184 PID: 2871736 at mm/slub.…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43408">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-43379 – In the Linux kernel, the following vulnerability has been resolved:

ksmbd: fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43379</guid>
    <pubDate>Fri, 08 May 2026 15:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-43379</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free in smb_lazy_parent_lease_break_close()  opinfo pointer obtained via rcu_dereference(fp->f_opinfo) is being accessed after rcu_read_unlock() has been called. This creates a race condition where the memory could be freed by a concurrent writer between the unlock and the subsequent pointer dereferences (op…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44113 – OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44113</guid>
    <pubDate>Wed, 06 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44113</strong></p>
  <p>OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and access unauthorized file contents.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-44112 – OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44112</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44112</guid>
    <pubDate>Wed, 06 May 2026 20:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-44112</strong></p>
  <p>OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in OpenShell sandbox filesystem writes that allows attackers to redirect writes outside the intended mount root. Attackers can exploit symlink swaps during filesystem operations to bypass sandbox restrictions and write files outside the local mount root.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44112">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43232 – In the Linux kernel, the following vulnerability has been resolved:

net: wan: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43232</guid>
    <pubDate>Wed, 06 May 2026 12:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43232</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets  When the FarSync T-series card is being detached, the fst_card_info is deallocated in fst_remove_one(). However, the fst_tx_task or fst_int_task may still be running or pending, leading to use-after-free bugs when the already freed fst_card_info is accesse…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43203 – In the Linux kernel, the following vulnerability has been resolved:

atm: fore20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43203</guid>
    <pubDate>Wed, 06 May 2026 12:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43203</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  atm: fore200e: fix use-after-free in tasklets during device removal  When the PCA-200E or SBA-200E adapter is being detached, the fore200e is deallocated. However, the tx_tasklet or rx_tasklet may still be running or pending, leading to use-after-free bug when the already freed fore200e is accessed again in fore200e_tx_tasklet()…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-34596 – Sandboxie-Plus is an open source sandbox-based isolation software for Windows. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34596</guid>
    <pubDate>Tue, 05 May 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-34596</strong></p>
  <p>Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation. When a user installs an addon through the SandMan interface, UpdUtil.exe is spawned as SYSTEM by SbieSvc but stages files in the user-writable %TEMP%\sandboxie-updater directory. After UpdUtil verifi…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-6180 – A race condition exists in PaperCut MF when processing badge-swipe data from cer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6180</guid>
    <pubDate>Tue, 05 May 2026 07:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-6180</strong></p>
  <p>A race condition exists in PaperCut MF when processing badge-swipe data from certain HP multifunction devices. Under specific network conditions involving dropped packets and out-of-order sequence counters, the server may incorrectly process fragmented data chunks. If a sequence reset notification fails to reach the server, the server may reject the initial data chunk while erroneously accepting…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-37531 – AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-37531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-37531</guid>
    <pubDate>Fri, 01 May 2026 17:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-37531</strong></p>
  <p>AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename function in wgtpkg-zip.c validates ZIP entry names but does not check for dot notation directory traversal sequences it only blocks absolute paths. The zread extraction function uses openat(workdirfd, f…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-37531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43050 – In the Linux kernel, the following vulnerability has been resolved:

atm: lec: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43050</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43050</guid>
    <pubDate>Fri, 01 May 2026 15:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43050</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  atm: lec: fix use-after-free in sock_def_readable()  A race condition exists between lec_atm_close() setting priv->lecd to NULL and concurrent access to priv->lecd in send_to_lecd(), lec_handle_bridge(), and lec_atm_send(). When the socket is freed via RCU while another thread is still using it, a use-after-free occurs in sock_d…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43050">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-43023 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43023</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43023</guid>
    <pubDate>Fri, 01 May 2026 15:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-43023</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: SCO: fix race conditions in sco_sock_connect()  sco_sock_connect() checks sk_state and sk_type without holding the socket lock. Two concurrent connect() syscalls on the same socket can both pass the check and enter sco_connect(), leading to use-after-free.  The buggy scenario involves three participants and was confir…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43023">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31761 – In the Linux kernel, the following vulnerability has been resolved:

iio: gyro: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31761</guid>
    <pubDate>Fri, 01 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31761</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  iio: gyro: mpu3050: Move iio_device_register() to correct location  iio_device_register() should be at the end of the probe function to prevent race conditions.  Place iio_device_register() at the end of the probe function and place iio_device_unregister() accordingly.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35155 – Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Pro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35155</guid>
    <pubDate>Wed, 29 Apr 2026 05:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35155</strong></p>
  <p>Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privileged attacker to gain elevated access.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31688 – In the Linux kernel, the following vulnerability has been resolved:

driver core...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31688</guid>
    <pubDate>Mon, 27 Apr 2026 18:16:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31688</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  driver core: enforce device_lock for driver_match_device()  Currently, driver_match_device() is called from three sites. One site (__device_attach_driver) holds device_lock(dev), but the other two (bind_store and __driver_attach) do not. This inconsistency means that bus match() callbacks are not guaranteed to be called with the…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3006 – Successful exploitation of the race condition vulnerability could allow
an attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3006</guid>
    <pubDate>Mon, 27 Apr 2026 03:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3006</strong></p>
  <p>Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31584 – In the Linux kernel, the following vulnerability has been resolved:

media: medi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31584</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31584</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31584</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: mediatek: vcodec: fix use-after-free in encoder release path  The fops_vcodec_release() function frees the context structure (ctx) without first cancelling any pending or running work in ctx->encode_work. This creates a race window where the workqueue handler (mtk_venc_worker) may still be accessing the context memory aft…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31584">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31578 – In the Linux kernel, the following vulnerability has been resolved:

media: as10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31578</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31578</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: as102: fix to not free memory after the device is registered in as102_usb_probe()  In as102_usb driver, the following race condition occurs: ``` 		CPU0						CPU1 as102_usb_probe()   kzalloc(); // alloc as102_dev_t   ....   usb_register_dev(); 						fd = sys_open("/path/to/dev"); // open as102 fd 						....   usb_deregiste…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31576 – In the Linux kernel, the following vulnerability has been resolved:

media: hack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31576</guid>
    <pubDate>Fri, 24 Apr 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31576</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  media: hackrf: fix to not free memory after the device is registered in hackrf_probe()  In hackrf driver, the following race condition occurs: ``` 		CPU0						CPU1 hackrf_probe()   kzalloc(); // alloc hackrf_dev   ....   v4l2_device_register();   .... 						fd = sys_open("/path/to/dev"); // open hackrf fd 						....   v4l2_devic…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35352 – A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo util...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35352</guid>
    <pubDate>Wed, 22 Apr 2026 17:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35352</strong></p>
  <p>A Time-of-Check to Time-of-Use (TOCTOU) race condition exists in the mkfifo utility of uutils coreutils. The utility creates a FIFO and then performs a path-based chmod to set permissions. A local attacker with write access to the parent directory can swap the newly created FIFO for a symbolic link between these two operations. This redirects the chmod call to an arbitrary file, potentially enabl…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41651 – PackageKit is a a D-Bus abstraction layer that allows the user to manage package...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41651</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41651</guid>
    <pubDate>Wed, 22 Apr 2026 14:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41651</strong></p>
  <p>PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41651">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31486 – In the Linux kernel, the following vulnerability has been resolved:

hwmon: (pmb...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31486</guid>
    <pubDate>Wed, 22 Apr 2026 14:16:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31486</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  hwmon: (pmbus/core) Protect regulator operations with mutex  The regulator operations pmbus_regulator_get_voltage(), pmbus_regulator_set_voltage(), and pmbus_regulator_list_voltage() access PMBus registers and shared data but were not protected by the update_lock mutex. This could lead to race conditions.  However, adding mutex…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41458 – OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41458</guid>
    <pubDate>Wed, 22 Apr 2026 03:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41458</strong></p>
  <p>OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a remote denial of service condition without requiring authentication.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40943 – Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40943</guid>
    <pubDate>Tue, 21 Apr 2026 22:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40943</strong></p>
  <p>Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server to panic with send on closed channel. The heartbeat() method uses a blocking channel send while holding a mutex, and under specific timing with concurrent close() calls, this can lead to either a deadlock (channel buffer full) or a panic…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41296 – OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41296</guid>
    <pubDate>Tue, 21 Apr 2026 00:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41296</strong></p>
  <p>OpenClaw before 2026.3.31 contains a time-of-check-time-of-use race condition in the remote filesystem bridge readFile function that allows sandbox escape. Attackers can exploit the separate path validation and file read operations to bypass sandbox restrictions and read arbitrary files.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33827 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33827</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33827</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33104 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33104</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33104</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32164 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32164</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32164</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32163 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32163</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32163</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32163</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32163">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32160 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32160</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32160</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32159 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32159</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32159</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32158 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32158</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32158</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32150 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32150</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32150</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32093 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32093</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32093</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32093</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32093">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32091 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32091</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32091</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32090 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32090</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32090</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32090</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech Brokered Api allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32090">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32086 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32086</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32086</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32086</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32086">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32083 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32083</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32083</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32083</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32083">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32082 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32082</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32082</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32082</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32082">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32068 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32068</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32068</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32068</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32068">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27929 – Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an aut...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27929</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27929</strong></p>
  <p>Time-of-check time-of-use (toctou) race condition in Windows LUAFV allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27927 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27927</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27927</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Projected File System allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27926 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27926</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27926</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27921 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27921</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27921</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27918 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27918</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27918</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-27911 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27911</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-27911</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows User Interface Core allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26174 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26174</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26174</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26173 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26173</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26173</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26172 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26172</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26172</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26168 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26168</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26168</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-26167 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26167</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-26167</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25184 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25184</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25184</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20930 – Concurrent execution using shared resource with improper synchronization ('race ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20930</guid>
    <pubDate>Tue, 14 Apr 2026 18:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20930</strong></p>
  <p>Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35554 – A race condition in the Apache Kafka Java producer client’s buffer pool manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35554</guid>
    <pubDate>Tue, 07 Apr 2026 14:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35554</strong></p>
  <p>A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics.  When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is prematurely deallocated and returned to the buffer pool. If a subsequent producer batch—potentially de…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35554">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54601 – An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54601</guid>
    <pubDate>Mon, 06 Apr 2026 21:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54601</strong></p>
  <p>An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a double free. An attacker can trigger a race condition by invoking an ioctl function concurrently from multiple threads.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54602 – An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54602</guid>
    <pubDate>Mon, 06 Apr 2026 20:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54602</strong></p>
  <p>An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a use-after-free. An attacker can trigger a race condition by invoking an ioctl function concurrently from multiple threads.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23461 – In the Linux kernel, the following vulnerability has been resolved:

Bluetooth: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23461</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23461</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23461</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user  After commit ab4eedb790ca ("Bluetooth: L2CAP: Fix corrupted list in hci_chan_del"), l2cap_conn_del() uses conn->lock to protect access to conn->users. However, l2cap_register_user() and l2cap_unregister_user() don't use conn->lock, creating a race condition where the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23461">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23454 – In the Linux kernel, the following vulnerability has been resolved:

net: mana: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23454</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23454</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown  A potential race condition exists in mana_hwc_destroy_channel() where hwc->caller_ctx is freed before the HWC's Completion Queue (CQ) and Event Queue (EQ) are destroyed. This allows an in-flight CQ interrupt handler to dereference freed memory, l…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23440 – In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23440</guid>
    <pubDate>Fri, 03 Apr 2026 16:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23440</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net/mlx5e: Fix race condition during IPSec ESN update  In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checking that the esn_event_arm field is 0x0, which indicates an event has occurred. After handling the ev…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-40849 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40849</guid>
    <pubDate>Thu, 02 Apr 2026 19:17:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-40849</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30332 – A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30332</guid>
    <pubDate>Thu, 02 Apr 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30332</strong></p>
  <p>A Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability in Balena Etcher for Windows prior to v2.1.4 allows attackers to escalate privileges and execute arbitrary code via replacing a legitimate script with a crafted payload during the flashing process.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33544 – Tinyauth is an authentication and authorization server. Prior to version 5.0.5, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33544</guid>
    <pubDate>Thu, 02 Apr 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33544</strong></p>
  <p>Tinyauth is an authentication and authorization server. Prior to version 5.0.5, all three OAuth service implementations (GenericOAuthService, GithubOAuthService, GoogleOAuthService) store PKCE verifiers and access tokens as mutable struct fields on singleton instances shared across all concurrent requests. When two users initiate OAuth login for the same provider concurrently, a race condition be…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35099 – Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35099</guid>
    <pubDate>Wed, 01 Apr 2026 16:23:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35099</strong></p>
  <p>Lakeside SysTrack Agent 11 before 11.5.0.15 has a race condition with resultant local privilege escalation to SYSTEM. The fixed versions are 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23410 – In the Linux kernel, the following vulnerability has been resolved:

apparmor: f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23410</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23410</guid>
    <pubDate>Wed, 01 Apr 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23410</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  apparmor: fix race on rawdata dereference  There is a race condition that leads to a use-after-free situation: because the rawdata inodes are not refcounted, an attacker can start open()ing one of the rawdata files, and at the same time remove the last reference to this rawdata (by removing the corresponding profile, for example…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23410">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32988 – OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32988</guid>
    <pubDate>Tue, 31 Mar 2026 12:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32988</strong></p>
  <p>OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability in fs-bridge staged writes where temporary file creation and population are not pinned to a verified parent directory. Attackers can exploit a race condition in parent-path alias changes to write attacker-controlled bytes outside the intended validated path before the final guarded replace step executes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-14031 – Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-14031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-14031</guid>
    <pubDate>Tue, 31 Mar 2026 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-14031</strong></p>
  <p>Sereal::Encoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library.  Sereal::Encoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922.  This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer small…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-14031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-14030 – Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-14030</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-14030</guid>
    <pubDate>Tue, 31 Mar 2026 12:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-14030</strong></p>
  <p>Sereal::Decoder versions from 4.000 through 4.009_002 for Perl embeds a vulnerable version of the Zstandard library.  Sereal::Decoder embeds a version of the Zstandard (zstd) library that is vulnerable to CVE-2019-11922.  This is a race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer small…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-14030">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33028 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33028</guid>
    <pubDate>Mon, 30 Mar 2026 18:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33028</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui application is vulnerable to a Race Condition. Due to the complete absence of synchronization mechanisms (Mutex) and non-atomic file writes, concurrent requests lead to the severe corruption of the primary configuration file (app.ini). This vulnerability results in a persistent Denial of Service (DoS)…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33872 – elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerabil...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33872</guid>
    <pubDate>Fri, 27 Mar 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33872</strong></p>
  <p>elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request-response correlation creates a "stale response" vulnerability. Because the worker does not verify which request a response belongs to, it may return the next a…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23393 – In the Linux kernel, the following vulnerability has been resolved:

bridge: cfm...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23393</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23393</guid>
    <pubDate>Wed, 25 Mar 2026 11:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23393</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  bridge: cfm: Fix race condition in peer_mep deletion  When a peer MEP is being deleted, cancel_delayed_work_sync() is called on ccm_rx_dwork before freeing. However, br_cfm_frame_rx() runs in softirq context under rcu_read_lock (without RTNL) and can re-schedule ccm_rx_dwork via ccm_rx_timer_start() between cancel_delayed_work_s…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23393">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28891 – A race condition was addressed with additional validation. This issue is fixed i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28891</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28891</strong></p>
  <p>A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be able to break out of its sandbox.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28891">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
