CVE-2026-26174High· 7.0▾ TwilightConcurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
windows_10_1607 < 10.0.14393.9060windows_10_1809 < 10.0.17763.8644windows_10_21h2 < 10.0.19044.7184windows_10_22h2 < 10.0.19045.7184windows_11_23h2 < 10.0.22631.6936windows_11_24h2 < 10.0.26100.8246windows_11_25h2 < 10.0.26200.8246windows_11_26h1 < 10.0.28000.1836windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.9060windows_server_2019 < 10.0.17763.8644windows_server_2022 < 10.0.20348.5020windows_server_2022_23h2 < 10.0.25398.2274windows_server_2025 < 10.0.26100.32690Upgrade past the affected range:
windows_10_1607 10.0.14393.9060windows_10_1809 10.0.17763.8644windows_10_21h2 10.0.19044.7184windows_10_22h2 10.0.19045.7184windows_11_23h2 10.0.22631.6936windows_11_24h2 10.0.26100.8246windows_11_25h2 10.0.26200.8246windows_11_26h1 10.0.28000.1836windows_server_2016 10.0.14393.9060windows_server_2019 10.0.17763.8644windows_server_2022 10.0.20348.5020windows_server_2022_23h2 10.0.25398.2274windows_server_2025 10.0.26100.32690Connected by shared product, vendor, weakness, or advisory.
CVE-2026-69364High· 7.1Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges over a network.
CVE-2026-69385High· 7.0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
CVE-2026-69319High· 7.0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Video Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-68840High· 7.0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows USB Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-50349High· 7.0Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVE-2026-85360High· 7.0Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.