OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100758

CRITICAL · CVSS 9.6 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A sandbox escape vulnerability exists in the Navigation component of Firefox, potentially allowing attackers to bypass security restrictions and execute arbitrary code within the browser environment. Users of affected Firefox versions, particularly those running older releases, should prioritize updating to the fixed versions (Firefox ESR 153.4, 157, ESR 115.42, or ESR 140.17) to mitigate the risk of exploitation. This issue is critical for organizations relying on Firefox for secure browsing, as it could lead to significant security breaches.

CVE
CVE-2026-100758
Severity
CRITICAL
CVSS
9.6
EPSS
0.32%
Firefox

Original NVD Description

Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.