DIRAS TAKE
Urgent: public exploit code is available and the flaw allows remote code execution with no user interaction, so prioritize containment and patching when Mozilla issues fixes.
What is CVE-2026-74943?
A remote attacker can cause arbitrary code execution in Mozilla Firefox by triggering a use-after-free bug in the Graphics: ImageLib component (CVE-2026-74943). The vulnerability is categorized as CWE-416 and scores 9.8 CVSS 3.1, indicating attacker-controlled remote network access, no privileges or user interaction required. The facts provided do not list specific affected Firefox versions or fixed releases, so which exact releases are affected is not specified here. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-74943 being exploited?
Public exploit code is available.
How to fix CVE-2026-74943
- Follow Mozilla security advisories and apply vendor updates as soon as a patch is released.
- Until a vendor fix is applied, reduce exposure by blocking or filtering access to untrusted sites and restrict Firefox network access where feasible.
- Enable and enforce automatic updates for Firefox clients and audit update status across endpoints.
- Monitor endpoint and network logs for exploit indicators and unusual process crashes or code execution originating from Firefox.
Frequently asked questions
Is CVE-2026-74943 being actively exploited?
Public exploit code for CVE-2026-74943 is available, but the facts provided do not include authoritative public reports that it is being actively exploited as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-74943?
The facts here do not list specific affected Firefox versions; consult Mozilla's official advisory for an authoritative affected-versions list when it is published.
Is there a patch for CVE-2026-74943?
According to the provided facts, a vendor patch is not marked as available; apply vendor updates as soon as Mozilla issues a fixed release.
Does CVE-2026-74943 require authentication?
No. The provided CVSS details indicate no privileges or user interaction are required, so the flaw can be triggered without authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-74943
- cve.org/CVERecord?id=CVE-2026-74943
- bugzilla.mozilla.org/show_bug.cgi?id=2057308
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-75
- mozilla.org/security/advisories/mfsa2026-76
- mozilla.org/security/advisories/mfsa2026-77
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-79
- mozilla.org/security/advisories/mfsa2026-80
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026