Junglewise Threat Intelligence

CVE-2026-92036: Mozilla Firefox incorrect boundary conditions in HTTP networking

CVE-2026-92036 · Severity: critical · CVSS 9.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird's HTTP networking component contains an incorrect boundary conditions vulnerability that could allow attackers to cause memory corruption. This could lead to browser crashes or potentially enable attackers to execute arbitrary code with browser privileges, affecting user data integrity and system security.

Technical details

The vulnerability is a boundary condition error in the Networking: HTTP component of Firefox and Thunderbird. Boundary condition flaws occur when code fails to properly validate input lengths or array bounds, potentially leading to out-of-bounds memory access. The flaw was patched in Firefox 156 and Thunderbird 156. The reported CVSS score of 9.8 indicates network-exploitable code execution risk. No public information indicates active exploitation in the wild at time of publication.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Thunderbird before 156

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156

References

Related threats