Junglewise Threat Intelligence

CVE-2026-92078: Mozilla Firefox denial-of-service in Security component

CVE-2026-92078 · Severity: medium · CVSS 6.5 · Published 2026-09-15

Executive brief

Firefox and Thunderbird include a Security component that processes cryptographic and validation operations. A denial-of-service vulnerability in this component allows attackers to crash or hang the browser/email client without requiring user interaction, affecting availability and productivity. Mozilla addressed this issue in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Technical details

This is a denial-of-service vulnerability in the Security component of Firefox and Thunderbird. The vulnerability allows an attacker to trigger a crash or hang condition in the Security component, resulting in denial of service to the affected applications. The attack vector is network-based, and the vulnerability does not require prior authentication. While the specific root cause is not fully disclosed in the available references, the CVSS score of 6.5 indicates a moderate-to-high severity impact on availability. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, Thunderbird 153.3

References

Related threats