OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100809

HIGH · CVSS 8.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A same-origin policy bypass vulnerability in the DevTools component of Firefox could allow attackers to access restricted data from different origins, potentially leading to unauthorized information disclosure. Users and organizations utilizing affected versions of Firefox should prioritize updating to Firefox ESR 153.4 or Firefox 157 to mitigate the risk of exploitation.

CVE
CVE-2026-100809
Severity
HIGH
CVSS
8.1
EPSS
0.15%
Firefox

Original NVD Description

Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

Related CVEs

Other vulnerabilities affecting the same vendor(s)