DIRAS TAKE
Treat this as high priority: the bug allows unauthenticated remote code execution over the network and no patch is recorded in the supplied facts, so reduce exposure until vendor fixes are applied.
What is CVE-2026-74964?
A remote attacker can trigger an integer overflow in Firefox that may allow execution of arbitrary code and full compromise of the browser (CVE-2026-74964). The flaw is classified as CWE-190 (integer overflow) and has a CVSS 3.1 vector indicating network access with no privileges or user interaction required. Specific affected Firefox builds are not listed in the provided facts; an attacker only needs network access to reach the vulnerable component.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-74964 being exploited?
There are no public reports of exploitation or public exploit code as of 2026-09-29.
How to fix CVE-2026-74964
- Apply official vendor updates when Mozilla releases a patch for CVE-2026-74964.
- Temporarily restrict network exposure to Firefox instances (block access to untrusted sites, use network filtering).
- Enable or enforce automatic updates for Firefox to ensure rapid deployment of the vendor fix.
- Monitor endpoint and network logs for crashes or unusual process behavior from Firefox and isolate affected hosts.
Frequently asked questions
Is CVE-2026-74964 being actively exploited?
There are no public reports of active exploitation or public exploit code for CVE-2026-74964 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-74964?
The provided facts do not include a vendor-published list of affected Firefox versions, so specific impacted builds are not available here.
Is there a patch for CVE-2026-74964?
No patch is recorded in the supplied facts for CVE-2026-74964; apply vendor updates when Mozilla issues a fix.
Does CVE-2026-74964 require authentication?
No; the vulnerability's metrics indicate no privileges and no user interaction are required, so it can be triggered without authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-74964
- cve.org/CVERecord?id=CVE-2026-74964
- bugzilla.mozilla.org/show_bug.cgi?id=2053327
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-76
- mozilla.org/security/advisories/mfsa2026-77
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-79
- mozilla.org/security/advisories/mfsa2026-80
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026