SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-54112

HIGH · CVSS 7.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A race condition vulnerability in the Windows Win32K component allows authorized attackers to exploit improper synchronization of shared resources, leading to potential local privilege escalation. This could enable attackers to gain elevated permissions on affected systems, compromising security and control. Organizations using Windows should prioritize patching this vulnerability to mitigate the risk of unauthorized access and system manipulation.

CVE
CVE-2026-54112
Severity
HIGH
CVSS
7.8
EPSS
0.15%
Windows

Original NVD Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)