Junglewise Threat Intelligence

CVE-2026-54999: Microsoft Windows TCP/IP race condition remote code execution

CVE-2026-54999 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the networking component of Microsoft Windows that could allow an attacker to take control of a computer. To exploit this, an attacker must be on the same local network (such as the same Wi-Fi or office network) as the target device. If successful, the attacker could execute malicious code, potentially leading to data theft or full system compromise.

Technical details

This vulnerability is classified as a race condition (CWE-362) within the Windows TCP/IP stack, occurring due to improper synchronization during concurrent execution using shared resources. An unauthenticated attacker can exploit this flaw by sending specially crafted network traffic over an adjacent network (Layer 2 reachability). Successful exploitation allows for remote code execution in the context of the kernel. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD

References

Related threats