CVE-2026-2771Critical· 9.8▾ MidnightUndefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Undefined behavior in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.
firefox < 115.33.0firefox < 148.0firefox >= 128.0, < 140.8.0thunderbird < 140.8.0thunderbird < 148.0Upgrade past the affected range:
firefox 140.8.0thunderbird 148.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-2447High· 8.8Heap buffer overflow in libvpx
CVE-2026-92072Low· 3.4Incorrect boundary conditions in the Safe Browsing component
CVE-2026-8092High· 8.1Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1
CVE-2026-12298Medium· 5.4Memory safety bug fixed in Firefox 152
CVE-2026-74961Critical· 9.1Side-channel in the Web Audio component
CVE-2026-74983High· 8.1Mitigation bypass in the Data Loss Prevention component