Junglewise Threat Intelligence

CVE-2026-92076: Mozilla Firefox incorrect boundary conditions in Networking

CVE-2026-92076 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird's networking layer contains an incorrect boundary condition vulnerability that could allow attackers to execute code or cause crashes. This affects the core networking stack used to handle web connections in these popular web browser and email client applications, with potential impact on availability and system security.

Technical details

CVE-2026-92076 is an incorrect boundary condition vulnerability in the Networking component of Firefox and Thunderbird. The vulnerability exists in how the networking layer handles buffer boundaries, which could be exploited to cause memory corruption or privilege escalation. The vulnerability is reachable via network attack vectors without requiring user authentication. Mozilla has issued patches in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. There are no reports of active exploitation in the wild as of the advisory date.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92076 publicly disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats