• PoC PUBLIC

CVE-2026-74936: pre-auth remote code execution in Mozilla Firefox

A remote attacker can execute arbitrary code in Firefox by exploiting a use-after-free bug in the WebAssembly component. CVE-2026-74936 has a critical CVSS 3.1 rating and the available data shows the flaw allows network-based exploitation with no privileges and no user interaction required. Specific affected Firefox builds are not listed in the provided facts; as of 2026-09-29 no vendor patch is recorded here.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00592
CWE
CWE-416
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code is available, so prioritize temporary mitigations and monitoring until an official fix is applied.

What is CVE-2026-74936?

A remote attacker can execute arbitrary code in Firefox by exploiting a use-after-free bug in the WebAssembly component. CVE-2026-74936 has a critical CVSS 3.1 rating and the available data shows the flaw allows network-based exploitation with no privileges and no user interaction required. Specific affected Firefox builds are not listed in the provided facts; as of 2026-09-29 no vendor patch is recorded here. The weakness is classified as CWE-416 (Use After Free).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74936 being exploited?

Public exploit code is available.

How to fix CVE-2026-74936

  1. Restrict exposure of Firefox installations to untrusted sites and networks using web filtering or proxy controls.
  2. Apply network-level protections and monitoring to detect exploit attempts against browsers.
  3. Follow Mozilla security advisories and apply vendor updates immediately when a patch is released.
  4. Harden endpoints and consider browser configuration policies that reduce attack surface until a fix is available.

Frequently asked questions

Is CVE-2026-74936 being actively exploited?

Public exploit code for CVE-2026-74936 exists, indicating a higher risk of active exploitation against Firefox.

Which Firefox versions are affected by CVE-2026-74936?

The provided facts do not list specific affected Firefox versions.

Is there a patch for CVE-2026-74936?

There is no patch listed in the provided facts as of 2026-09-29; monitor Mozilla advisories and apply updates when published.

Does CVE-2026-74936 require authentication?

No; the vulnerability in Firefox can be exploited without authentication or user interaction according to the available vulnerability data.

References