SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-54107

HIGH · CVSS 8.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A race condition vulnerability in the Windows Win32K component allows authorized attackers to exploit improper synchronization, potentially leading to local privilege escalation. This high-severity flaw (CVSS 8.8) poses a significant risk to systems running affected versions of Windows. Organizations using these systems should prioritize patching to mitigate the risk of unauthorized access and control.

CVE
CVE-2026-54107
Severity
HIGH
CVSS
8.8
EPSS
0.15%
Windows

Original NVD Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)