DIRAS TAKE
High urgency: this flaw requires no authentication or user interaction, so exposed Firefox installations should be treated as high risk until vendor updates are applied.
What is CVE-2026-74979?
An unauthenticated remote attacker can bypass protections in Firefox's Add-ons Manager and gain full impact on confidentiality, integrity, and availability (CVE-2026-74979). The issue is a mitigation bypass in the browser's add-ons management component that affects Firefox (and related Thunderbird builds), and it requires no privileges or user interaction to exploit over a network according to the published CVSS vector. Specific affected version ranges are not listed in these facts; the vendor has acknowledged the problem but a patch is not recorded here.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-74979 being exploited?
There are no public reports of active exploitation as of 2026-09-29.
How to fix CVE-2026-74979
- Limit network exposure of vulnerable Firefox installations and block untrusted network sources.
- Apply vendor guidance and install official updates as soon as Mozilla releases them.
- Monitor logs and intrusion detection for suspicious activity related to browser add-ons and process launches.
- Consider temporary enterprise controls that restrict add-on installation or management until a patch is available.
Frequently asked questions
Is CVE-2026-74979 being actively exploited?
There are no public reports of active exploitation of CVE-2026-74979 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-74979?
These facts note a mitigation bypass in the Add-ons Manager affecting Firefox and related Thunderbird builds, but they do not list specific affected version ranges or fixed versions.
Is there a patch for CVE-2026-74979?
A patch is not recorded in these facts; the vendor has acknowledged the issue but no available fix is listed here.
Does CVE-2026-74979 require authentication?
No — the published CVSS vector indicates no privileges and no user interaction are required, so exploitation can be attempted without authentication or a user click.
References
- nvd.nist.gov/vuln/detail/CVE-2026-74979
- cve.org/CVERecord?id=CVE-2026-74979
- bugzilla.mozilla.org/show_bug.cgi?id=2045676
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-77
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-80
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026