CVE-2026-74987: pre-auth memory corruption in Mozilla Firefox

A remote attacker can trigger memory corruption in Mozilla Firefox, potentially enabling remote code execution (CVE-2026-74987). The underlying issue is a CWE-119 memory-safety defect that can be reached remotely over the network; the vendor notes fixes were released in Firefox 154 and related ESR and Thunderbird updates. An attacker needs only network access to target a vulnerable browser because no privileges or user interaction are required.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00715
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

High priority — the flaw is a remote, pre-auth memory-corruption bug (no user interaction) so restrict network exposure of browsers and apply the vendor updates referenced in Mozilla's advisory immediately.

What is CVE-2026-74987?

A remote attacker can trigger memory corruption in Mozilla Firefox, potentially enabling remote code execution (CVE-2026-74987). The underlying issue is a CWE-119 memory-safety defect that can be reached remotely over the network; the vendor notes fixes were released in Firefox 154 and related ESR and Thunderbird updates. An attacker needs only network access to target a vulnerable browser because no privileges or user interaction are required.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74987 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-74987

  1. Apply the vendor updates referenced in Mozilla's advisory as soon as they are available to your environment.
  2. Limit exposure of Firefox to untrusted networks and block unneeded inbound connections to hosts running the browser.
  3. Enable browser sandboxing, endpoint exploit mitigations, and monitoring for crashes or unusual memory-corruption indicators.
  4. Log and investigate browser crashes and related telemetry for signs of exploitation.

Frequently asked questions

Is CVE-2026-74987 being actively exploited?

There are no public reports of exploitation of CVE-2026-74987 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-74987?

Vendor information indicates the issue affected recent Firefox releases and that fixes were released in Firefox 154 and corresponding ESR and Thunderbird updates.

Does CVE-2026-74987 require authentication?

No — the vulnerability can be reached remotely without authentication or user interaction.

What can an attacker do with CVE-2026-74987?

The memory-corruption bug can allow an attacker to execute arbitrary code, crash the browser, or otherwise compromise the affected Firefox process's confidentiality, integrity, and availability.

References