Junglewise Threat Intelligence

CVE-2026-92057: Mozilla Firefox mitigation bypass in Enterprise Policies component

CVE-2026-92057 · Severity: critical · CVSS 9.1 · Published 2026-09-15

Executive brief

Firefox and Thunderbird include an Enterprise Policies component used to enforce security and configuration controls in corporate environments. A mitigation bypass vulnerability in this component could allow an attacker to circumvent critical security protections, potentially leading to unauthorized access or malicious code execution on managed systems.

Technical details

CVE-2026-92057 is a mitigation bypass vulnerability in the Enterprise Policies component of Mozilla Firefox and Thunderbird. The vulnerability allows an attacker to circumvent security protections or controls that are enforced through the Enterprise Policies mechanism, which is designed to apply centralized security policies in managed deployments. The attack vector appears to be network-based, potentially exploitable remotely without requiring user interaction or authentication. Successful exploitation could allow an attacker to disable or bypass critical security mitigations, leading to privilege escalation or further compromise of the affected system. The vulnerability has been patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird ESR before 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92057 publicly disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3

References

Related threats