OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100787

CRITICAL · CVSS 9.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A sandbox escape vulnerability in the XUL component of Firefox allows attackers to potentially bypass security restrictions, leading to unauthorized access to system resources. Users of affected Firefox versions should prioritize updates to Firefox ESR 153.4 or Firefox 157 to mitigate the risk of exploitation. This issue is particularly critical for organizations relying on Firefox for secure browsing, as it could compromise sensitive data and system integrity.

CVE
CVE-2026-100787
Severity
CRITICAL
CVSS
9.6
EPSS
0.30%
Firefox

Original NVD Description

Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

Related CVEs

Other vulnerabilities affecting the same vendor(s)