# CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

**Likelihood of exploit:** Medium · **KEV-linked**

> As of 2026-10-05, CWE-362 (Race Condition) underlies 17 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 48 tracked threats. MITRE rates its likelihood of exploit as Medium.

**Last updated:** 2026-10-05

## What is CWE-362?

The product contains a concurrent code sequence that requires temporary, exclusive access to a shared resource, but a timing window exists in which the shared resource can be modified by another code sequence operating concurrently.

A race condition occurs within concurrent environments, and it is effectively a property of a code sequence. Depending on the context, a code sequence may be in the form of a function call, a small number of instructions, a series of program invocations, etc. A race condition violates these properties, which are closely related: Exclusivity - the code sequence is given exclusive access to the shared resource, i.e., no other code sequence can modify properties of the shared resource before the original sequence has completed execution. Atomicity - the code sequence is behaviorally atomic, i.e., no other thread or process can concurrently execute the same sequence of instructions (or a subset) against the same resource. A race condition exists when an "interfering code sequence" can still access the shared resource, violating exclusivity. The interfering code sequence could be "trusted" or "untrusted." A trusted interfering code sequence occurs within the product; it cannot be modified by the attacker, and it can only be invoked indirectly. An untrusted interfering code sequence can be authored directly by the attacker, and typically it is external to the vulnerable product.

CWE-362 is a class-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Language: C; Language: C++; Language: Java; Technology: Mobile; Technology: ICS/OT.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/362.html) (CWE-362 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Availability** — DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory), DoS: Resource Consumption (Other). When a race condition makes it possible to bypass a resource cleanup routine or trigger multiple initialization routines, it may lead to resource exhaustion.
- **Availability** — DoS: Crash, Exit, or Restart, DoS: Instability. When a race condition allows multiple control flows to access a resource simultaneously, it might lead the product(s) into unexpected states, possibly resulting in a crash.
- **Confidentiality, Integrity** — Read Files or Directories, Read Application Data. When a race condition is combined with predictable resource names and loose permissions, it may be possible for an attacker to overwrite or access confidential data (CWE-59).
- **Access Control** — Execute Unauthorized Code or Commands, Gain Privileges or Assume Identity, Bypass Protection Mechanism. This can have security implications when the expected synchronization is in security-critical code, such as recording whether a user is authenticated or modifying important state information that should not be influenced by an outsider.

_Source: MITRE CWE, common consequences._

## How CWE-362 is exploited in the wild

Threadlinqs maps 17 CVEs to CWE-362, published between 2016-11-10 and 2026-10-04. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 9 high, 7 medium, 1 low. The highest EPSS score in the set is 93.9% (CVE-2016-5195), the modelled probability of exploitation in the next 30 days. 48 tracked threats reference CWE-362 directly or through a CVE it covers; the most recent is “Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60” (2026-10-02). Affected products concentrate in Microsoft (5), zephyrproject (2), Apple (1), among 16 vendors in total.

## Vulnerabilities (CVEs)

All 17 CVEs mapped to CWE-362, CISA KEV first, then by CVSS score.

- [CVE-2023-36884](https://intel.threadlinqs.com/cve/CVE-2023-36884) — CISA KEV · CVSS 7.5 high · EPSS 93.2% · published 2023-07-11
- [CVE-2016-5195](https://intel.threadlinqs.com/cve/CVE-2016-5195) — CISA KEV · CVSS 7 high · EPSS 93.9% · published 2016-11-10
- [CVE-2026-42913](https://intel.threadlinqs.com/cve/CVE-2026-42913) — CVSS 7.5 high · EPSS 0.4% · published 2026-06-09
- [CVE-2026-42909](https://intel.threadlinqs.com/cve/CVE-2026-42909) — CVSS 7.5 high · EPSS 0.3% · published 2026-06-09
- [CVE-2026-32161](https://intel.threadlinqs.com/cve/CVE-2026-32161) — CVSS 7.5 high · EPSS 0.0% · published 2026-05-12
- [CVE-2026-5947](https://intel.threadlinqs.com/cve/CVE-2026-5947) — CVSS 7.5 high · EPSS 0.0% · published 2026-05-20
- [CVE-2022-46689](https://intel.threadlinqs.com/cve/CVE-2022-46689) — CVSS 7 high · EPSS 85.3% · published 2022-12-15
- [CVE-2026-23668](https://intel.threadlinqs.com/cve/CVE-2026-23668) — CVSS 7 high · EPSS 0.0% · published 2026-03-10
- [CVE-2026-10681](https://intel.threadlinqs.com/cve/CVE-2026-10681) — CVSS 6.5 medium · EPSS 0.0% · published 2026-07-25
- [CVE-2026-54778](https://intel.threadlinqs.com/cve/CVE-2026-54778) — CVSS 6.2 medium · EPSS 0.1% · published 2026-07-08
- [CVE-2026-94043](https://intel.threadlinqs.com/cve/CVE-2026-94043) — CVSS 5.3 medium · EPSS 0.3% · published 2026-09-20
- [CVE-2026-105112](https://intel.threadlinqs.com/cve/CVE-2026-105112) — CVSS 5.3 medium · published 2026-10-03
- [CVE-2026-105163](https://intel.threadlinqs.com/cve/CVE-2026-105163) — CVSS 5.3 medium · published 2026-10-04
- [CVE-2026-13502](https://intel.threadlinqs.com/cve/CVE-2026-13502) — CVSS 4.5 medium · EPSS 0.0% · published 2026-06-28
- [CVE-2026-7366](https://intel.threadlinqs.com/cve/CVE-2026-7366) — CVSS 4.2 medium · published 2026-08-12
- [CVE-2026-11812](https://intel.threadlinqs.com/cve/CVE-2026-11812) — CVSS 2.5 low · EPSS 0.0% · published 2026-08-10
- [CVE-2026-4368](https://intel.threadlinqs.com/cve/CVE-2026-4368) — high · EPSS 0.0% · published 2026-03-23

## Affected vendors

- [Microsoft](https://intel.threadlinqs.com/vendors/microsoft) — 5 CVEs
- [zephyrproject](https://intel.threadlinqs.com/vendors/zephyrproject) — 2 CVEs
- [Apple](https://intel.threadlinqs.com/vendors/apple) — 1 CVE
- [Canonical](https://intel.threadlinqs.com/vendors/canonical) — 1 CVE
- [Citrix](https://intel.threadlinqs.com/vendors/citrix) — 1 CVE
- [CoreWCF](https://intel.threadlinqs.com/vendors/corewcf) — 1 CVE
- [Debian](https://intel.threadlinqs.com/vendors/debian) — 1 CVE
- [Fedoraproject](https://intel.threadlinqs.com/vendors/fedoraproject) — 1 CVE
- [IBM](https://intel.threadlinqs.com/vendors/ibm) — 1 CVE
- [ISC](https://intel.threadlinqs.com/vendors/isc) — 1 CVE
- [Linux](https://intel.threadlinqs.com/vendors/linux) — 1 CVE
- **Paloaltonetworks** — 1 CVE

## Threat activity

48 tracked threats cite CWE-362; the 25 most recent are listed.

- [Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60](https://intel.threadlinqs.com/threat/TL-2026-2841) — MEDIUM · 2026-10-02
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — CRITICAL · 2026-09-27
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables SNAT Privilege Escalation, and AF_ALG Race Condition (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964)](https://intel.threadlinqs.com/threat/TL-2026-2582) — CRITICAL · 2026-09-19
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential Databases (CVE-2024-21762 Toolkit Staged)](https://intel.threadlinqs.com/threat/TL-2026-2514) — HIGH · 2026-09-15
- [Apple Ships 273-CVE Coordinated Security Update Across iOS 27, macOS, watchOS, tvOS, visionOS, Safari, and Xcode — Bundles a Previously KEV-Listed Pre-Auth Screen Sharing RCE](https://intel.threadlinqs.com/threat/TL-2026-2522) — CRITICAL · 2026-09-15
- [EtherHiding: Blockchain-Based C2 on Polygon Fuels ClickFix Backdoor + Banking-Trojan Extension Campaign Adopted by Criminal, North Korean, and Iran-Linked Actors](https://intel.threadlinqs.com/threat/TL-2026-2273) — HIGH · 2026-09-01
- [ShieldBreak: Windows Defender Cloud-Hydration Zero-Day Bypasses RoguePlanet Patch (CVE-2026-50656) for SYSTEM-Level Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2020) — CRITICAL · 2026-08-14
- [PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)](https://intel.threadlinqs.com/threat/TL-2026-2006) — HIGH · 2026-08-13
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)](https://intel.threadlinqs.com/threat/TL-2026-1987) — CRITICAL · 2026-08-11
- [Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service (CVE-2026-42492, CVE-2026-62428, CVE-2026-62431, CVE-2026-62432, CVE-2026-62434, CVE-2026-62435, CVE-2026-62436)](https://intel.threadlinqs.com/threat/TL-2026-1781) — HIGH · 2026-07-31
- [Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape / Local-Privilege-Escalation Bugs (CVE-2026-17650 – CVE-2026-17656)](https://intel.threadlinqs.com/threat/TL-2026-1770) — CRITICAL · 2026-07-30
- [RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)](https://intel.threadlinqs.com/threat/TL-2026-1629) — HIGH · 2026-07-22
- [CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to Root](https://intel.threadlinqs.com/threat/TL-2026-1633) — HIGH · 2026-07-22
- [IonStack: One-Click Firefox JIT-to-Linux-Kernel Root Exploit Chain (CVE-2026-10702 + CVE-2026-43499 "GhostLock") Demonstrated Against Android 17](https://intel.threadlinqs.com/threat/TL-2026-1477) — HIGH · 2026-07-18
- [F5OS / Traffix SDC Information Disclosure (CVE-2026-46333) — Linux Kernel ptrace/pidfd_getfd Race Condition, Public PoC (CHARON)](https://intel.threadlinqs.com/threat/TL-2026-1503) — HIGH · 2026-07-18
- [CVE-2026-46215: Linux Kernel DRM GEM_CHANGE_HANDLE Use-After-Free Local Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1504) — HIGH · 2026-07-18
- [LegacyHive: Unpatched Windows User Profile Service (ProfSvc) Local Privilege Escalation Zero-Day — Public PoC Bypasses Fully Patched Systems](https://intel.threadlinqs.com/threat/TL-2026-1445) — HIGH · 2026-07-17
- [LegacyHive: Windows 0-Day Local Privilege Escalation via User Profile Service (ProfSvc) Arbitrary Registry Hive Loading](https://intel.threadlinqs.com/threat/TL-2026-1449) — HIGH · 2026-07-17
- [Microsoft July 2026 Patch Tuesday: 570 Vulnerabilities Fixed, Including 2 Actively Exploited Zero-Days (CVE-2026-56164, CVE-2026-56155)](https://intel.threadlinqs.com/threat/TL-2026-1325) — CRITICAL · 2026-07-14
- [Microsoft July 2026 Patch Tuesday: Two Actively Exploited Zero-Days in AD FS and SharePoint (CVE-2026-56155, CVE-2026-56164)](https://intel.threadlinqs.com/threat/TL-2026-1336) — CRITICAL · 2026-07-14
- [CVE-2026-50746: Critical Unauthenticated Command Injection in Ubiquiti UniFi Connect Application (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1159) — CRITICAL · 2026-07-10
- [Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNS](https://intel.threadlinqs.com/threat/TL-2026-1184) — CRITICAL · 2026-07-10
- [Six AirDrop and Quick Share Proximity File-Transfer Vulnerabilities (Apple, Google, Samsung) — 'Protocol Prying' Research](https://intel.threadlinqs.com/threat/TL-2026-1197) — MEDIUM · 2026-07-10
- [Bad Epoll (CVE-2026-46242): Use-After-Free Zero-Day in Linux Kernel epoll Subsystem Enables Root Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1105) — HIGH · 2026-07-05
- [CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1140) — CRITICAL · 2026-06-30

## Mitigations

- **Architecture and Design**: In languages that support it, use synchronization primitives. Only wrap these around critical code to minimize the impact on performance.
- **Architecture and Design**: Use thread-safe capabilities such as the data access abstraction in Spring.
- **Architecture and Design**: Minimize the usage of shared resources in order to remove as much complexity as possible from the control flow and to reduce the likelihood of unexpected conditions occurring. Additionally, this will minimize the amount of synchronization necessary and may even help to reduce the likelihood of a denial of service where an attacker may be able to repeatedly trigger a critical section (CWE-400).
- **Implementation**: When using multithreading and operating on shared variables, only use thread-safe functions.
- **Implementation**: Use atomic operations on shared variables. Be wary of innocent-looking constructs such as "x++". This may appear atomic at the code layer, but it is actually non-atomic at the instruction layer, since it involves a read, followed by a computation, followed by a write.
- **Implementation**: Use a mutex if available, but be sure to avoid related weaknesses such as CWE-412.
- **Implementation**: Avoid double-checked locking (CWE-609) and other implementation errors that arise when trying to avoid the overhead of synchronization.
- **Implementation**: Disable interrupts or signals over critical parts of the code, but also make sure that the code does not go into a large or infinite loop.
- **Implementation**: Use the volatile type modifier for critical variables to avoid unexpected compiler optimization or reordering. This does not necessarily solve the synchronization problem, but it can help.
- **Architecture and Design, Operation / Environment Hardening**: Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database administrator, especially in day-to-day operations.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Black Box**: Black box methods may be able to identify evidence of race conditions via methods such as multiple simultaneous connections, which may cause the software to become instable or crash. However, race conditions with very narrow timing windows would not be detectable.
- **White Box**: Common idioms are detectable in white box analysis, such as time-of-check-time-of-use (TOCTOU) file operations (CWE-367), or double-checked locking (CWE-609).
- **Automated Dynamic Analysis** (effectiveness: Moderate): This weakness can be detected using dynamic tools and techniques that interact with the software using large test suites with many diverse inputs, such as fuzz testing (fuzzing), robustness testing, and fault injection. The software's operation may slow down, but it should not become unstable, crash, or generate incorrect results. Race conditions may be detected with a stress-test by calling the software simultaneously from a large number of threads or processes, and look for evidence of any…
- **Automated Static Analysis - Binary or Bytecode** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Bytecode Weakness Analysis - including disassembler + source code weakness analysis Cost effective for partial coverage: Binary Weakness Analysis - including disassembler + source code weakness analysis
- **Dynamic Analysis with Automated Results Interpretation** (effectiveness: SOAR Partial): According to SOAR [REF-1479], the following detection techniques may be useful: Cost effective for partial coverage: Web Application Scanner Web Services Scanner Database Scanners
- **Dynamic Analysis with Manual Results Interpretation** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Framework-based Fuzzer Cost effective for partial coverage: Fuzz Tester Monitored Virtual Environment - run potentially malicious code in sandbox / wrapper / virtual machine, see if it does anything suspicious
- **Manual Static Analysis - Source Code** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Manual Source Code Review (not inspections) Cost effective for partial coverage: Focused Manual Spotcheck - Focused manual analysis of source
- **Automated Static Analysis - Source Code** (effectiveness: High): According to SOAR [REF-1479], the following detection techniques may be useful: Highly cost effective: Source code Weakness Analyzer Context-configured Source Code Weakness Analyzer

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-662](https://cwe.mitre.org/data/definitions/662.html)
- [CWE-416 Use After Free](https://intel.threadlinqs.com/cwe/CWE-416)
- [CWE-476 NULL Pointer Dereference](https://intel.threadlinqs.com/cwe/CWE-476)

Canonical: https://intel.threadlinqs.com/cwe/CWE-362
Source definition: https://cwe.mitre.org/data/definitions/362.html
Detection rules and IOCs for threats exploiting CWE-362 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
