SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-68840

HIGH · CVSS 7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A race condition vulnerability in the Windows USB Driver allows an authorized attacker to exploit improper synchronization of shared resources, potentially leading to local privilege escalation. This high-severity flaw affects Windows systems and should be prioritized by organizations that utilize USB devices extensively, as it could enable attackers to gain elevated access to sensitive system functions. Immediate mitigation is recommended to safeguard against potential exploitation.

CVE
CVE-2026-68840
Severity
HIGH
CVSS
7
EPSS
0.16%
Windows

Original NVD Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)