CVE-2026-74964: pre-auth remote code execution in Mozilla Firefox

A remote attacker can trigger an integer overflow in Firefox that may allow execution of arbitrary code and full compromise of the browser (CVE-2026-74964). The flaw is classified as CWE-190 (integer overflow) and has a CVSS 3.1 vector indicating network access with no privileges or user interaction required. Specific affected Firefox builds are not listed in the provided facts; an attacker only needs network access to reach the vulnerable component.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00684
CWE
CWE-190
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority: the bug allows unauthenticated remote code execution over the network and no patch is recorded in the supplied facts, so reduce exposure until vendor fixes are applied.

What is CVE-2026-74964?

A remote attacker can trigger an integer overflow in Firefox that may allow execution of arbitrary code and full compromise of the browser (CVE-2026-74964). The flaw is classified as CWE-190 (integer overflow) and has a CVSS 3.1 vector indicating network access with no privileges or user interaction required. Specific affected Firefox builds are not listed in the provided facts; an attacker only needs network access to reach the vulnerable component.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74964 being exploited?

There are no public reports of exploitation or public exploit code as of 2026-09-29.

How to fix CVE-2026-74964

  1. Apply official vendor updates when Mozilla releases a patch for CVE-2026-74964.
  2. Temporarily restrict network exposure to Firefox instances (block access to untrusted sites, use network filtering).
  3. Enable or enforce automatic updates for Firefox to ensure rapid deployment of the vendor fix.
  4. Monitor endpoint and network logs for crashes or unusual process behavior from Firefox and isolate affected hosts.

Frequently asked questions

Is CVE-2026-74964 being actively exploited?

There are no public reports of active exploitation or public exploit code for CVE-2026-74964 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-74964?

The provided facts do not include a vendor-published list of affected Firefox versions, so specific impacted builds are not available here.

Is there a patch for CVE-2026-74964?

No patch is recorded in the supplied facts for CVE-2026-74964; apply vendor updates when Mozilla issues a fix.

Does CVE-2026-74964 require authentication?

No; the vulnerability's metrics indicate no privileges and no user interaction are required, so it can be triggered without authentication.

References