CVE-2026-75874 – Mozilla Firefox
CVSS 10
CRITICAL
Critical - Same Day Deployment
“A sandbox escape and a critical WebAssembly memory flaw create severe browser compromise risk.”
Mozilla fixes two Critical Firefox vulnerabilities. CVE-2026-75874 is a sandbox escape in the Remote Settings Client component and is fixed in Firefox 154. The CVSS score is 10.0, which is Critical severity. Firefox 155 fixes 29 other issues.
CVE-2026-74936 is a use-after-free vulnerability in the JavaScript WebAssembly component. It is fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1. The CVSS score is 9.8, which is Critical severity. Thunderbird 154, 140.14, and 153.1 also contain the corresponding fix.
Key Details
- Affected Product
- Mozilla Firefox
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-693
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.