OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100796

HIGH · CVSS 8.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the JavaScript: WebAssembly component affects Firefox and Java, allowing attackers to potentially execute arbitrary code. This high-severity flaw (CVSS 8.8) can lead to significant security breaches, making it crucial for users of affected products to prioritize updates, particularly those in environments where WebAssembly is utilized. Organizations relying on Firefox and Java should urgently apply the patch provided in Firefox version 157 to mitigate risks.

CVE
CVE-2026-100796
Severity
HIGH
CVSS
8.8
EPSS
0.30%
Firefox Java

Original NVD Description

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.