DIRAS TAKE
Urgent: this is a remotely triggerable, high-impact use-after-free with a CVSS 9.8 rating and no public exploit reported or vendor patch available yet; reduce exposure of internet-facing Firefox instances and prepare to apply vendor updates immediately when released.
What is CVE-2026-74944?
Remote attackers can execute arbitrary code in Firefox via a use-after-free in the DOM component, tracked as CVE-2026-74944. The bug affects releases fixed by the vendor in Firefox 154 and in the listed ESR releases, so versions prior to those fixes are vulnerable. The flaw is reachable over the network and requires no privileges or user interaction to trigger, enabling full compromise of the affected Firefox process if exploited. The weakness is classified as CWE-416 (Use After Free).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-74944 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-74944
- Restrict Firefox access from untrusted networks and block unneeded inbound connections.
- Apply the vendor's security guidance and install updates immediately when Mozilla releases patches.
- Monitor browser crash logs and endpoint telemetry for signs of exploitation or unexpected process crashes.
- Harden hosts running Firefox with mitigations such as sandboxing, limited privileges, and application allowlisting.
Frequently asked questions
Is CVE-2026-74944 being actively exploited?
There are no public reports of active exploitation of CVE-2026-74944 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-74944?
The vulnerability is a DOM use-after-free fixed by Mozilla in Firefox 154 and in the referenced ESR releases; versions prior to those fixes are affected.
Is there a patch for CVE-2026-74944?
As of 2026-09-29 a public patch was not available; Mozilla has indicated fixes in the cited releases but administrators should follow vendor announcements and apply official updates when published.
Does CVE-2026-74944 require authentication?
No, the issue can be triggered remotely without authentication or user interaction against vulnerable Firefox builds.
References
- nvd.nist.gov/vuln/detail/CVE-2026-74944
- cve.org/CVERecord?id=CVE-2026-74944
- bugzilla.mozilla.org/show_bug.cgi?id=2057778
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-76
- mozilla.org/security/advisories/mfsa2026-77
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-79
- mozilla.org/security/advisories/mfsa2026-80
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026