ThreatCluster

Multiple Race Condition Vulnerabilities in Windows Products Identified

First seen 8 Sep 2026, 20:13 UTC Api.Msrc.Microsoftwww.cve.org 57

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-61920 and CVE-2026-77894, have been disclosed by Microsoft. CVE-2026-61920 affects Windows DNS, allowing attackers to execute code over a network through a race condition, while CVE-2026-77894 impacts Windows Installer, enabling local privilege escalation to SYSTEM. Both vulnerabilities have high attack complexity, requiring attackers to exploit race conditions successfully. The vulnerabilities were released on August 11 and September 8, 2026, respectively. Microsoft has updated its advisory to clarify that CVE-2026-61920 only affects Windows Servers. Security professionals are advised to monitor for potential exploitation attempts and apply relevant patches as they become available.

Key Points: • CVE-2026-61920 allows remote code execution via Windows DNS. • CVE-2026-77894 enables local privilege escalation in Windows Installer. • Both vulnerabilities require successful exploitation of race conditions.

Ask AI about this cluster

Timeline

2026-08-11
CVE-2026-61920 published
Microsoft disclosed a race condition vulnerability in Windows DNS allowing remote code execution.
Api.Msrc.Microsoft
2026-09-08
CVE-2026-77894 published
Microsoft disclosed a race condition vulnerability in Windows Installer allowing local privilege escalation.
Api.Msrc.Microsoft