Junglewise Threat Intelligence

CVE-2026-92077: Mozilla Firefox denial-of-service in SVG component

CVE-2026-92077 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a vulnerability in their SVG (Scalable Vector Graphics) rendering component that can be exploited to cause a denial-of-service condition. When a user encounters a specially crafted SVG file or web page, an attacker can crash the application, disrupting productivity and user access to services relying on these applications. This has been patched in recent versions.

Technical details

CVE-2026-92077 is a denial-of-service vulnerability in the SVG component of Mozilla Firefox and Thunderbird. The vulnerability allows remote attackers to crash the affected application by triggering unspecified behavior in SVG rendering logic. The attack vector is network-based and requires user interaction (viewing a malicious SVG or web page). The vulnerability has been patched in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3, and there is no public evidence of active exploitation in the wild.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: Published on NVD and Mozilla security advisory
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats