Executive brief
Firefox is a widely-used web browser that handles network communications. A mitigation bypass vulnerability in its Networking component could allow attackers to circumvent security protections, potentially enabling exploitation of other weaknesses or unauthorized access to sensitive browser functionality.
Technical details
This vulnerability is classified as a mitigation bypass in the Networking component of Mozilla Firefox and related products. The exact root cause and attack preconditions are not disclosed in the available advisory content, but the critical severity and 9.1 CVSS score suggest a high-impact issue affecting core network handling. The vulnerability was patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. No evidence of active exploitation in the wild has been reported.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird before 153.3
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3