OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-100825

HIGH · CVSS 8.8 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the JavaScript Engine's JIT component affects Firefox and Java, allowing attackers to potentially execute arbitrary code. This high-severity flaw (CVSS 8.8) poses significant risks to users of affected versions, particularly those running outdated releases. Organizations and individuals using Firefox should prioritize updating to versions 153.4 ESR or 157 to mitigate the risk.

CVE
CVE-2026-100825
Severity
HIGH
CVSS
8.8
EPSS
0.25%
Firefox Java

Original NVD Description

Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.