CVE-2025-14330Critical· 9.8▾ MidnightJIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.
firefox < 140.6.0firefox < 146.0thunderbird < 140.6.0thunderbird < 146.0Upgrade past the affected range:
firefox 146.0thunderbird 146.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100819Critical· 9.6Sandbox escape due to incorrect boundary conditions in the XPCOM component
CVE-2026-100814High· 8.8Incorrect boundary conditions in the JavaScript Engine: JIT component
CVE-2026-100782High· 8.8Privilege escalation due to incorrect boundary conditions in the Graphics component
CVE-2026-100764High· 8.8Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component
CVE-2026-92076High· 8.8Incorrect boundary conditions in the Networking component
CVE-2026-92036Critical· 9.8Incorrect boundary conditions in the Networking: HTTP component