DIRAS TAKE
High priority — the flaw is a remote, pre-auth memory-corruption bug (no user interaction) so restrict network exposure of browsers and apply the vendor updates referenced in Mozilla's advisory immediately.
What is CVE-2026-74987?
A remote attacker can trigger memory corruption in Mozilla Firefox, potentially enabling remote code execution (CVE-2026-74987). The underlying issue is a CWE-119 memory-safety defect that can be reached remotely over the network; the vendor notes fixes were released in Firefox 154 and related ESR and Thunderbird updates. An attacker needs only network access to target a vulnerable browser because no privileges or user interaction are required.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-74987 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-74987
- Apply the vendor updates referenced in Mozilla's advisory as soon as they are available to your environment.
- Limit exposure of Firefox to untrusted networks and block unneeded inbound connections to hosts running the browser.
- Enable browser sandboxing, endpoint exploit mitigations, and monitoring for crashes or unusual memory-corruption indicators.
- Log and investigate browser crashes and related telemetry for signs of exploitation.
Frequently asked questions
Is CVE-2026-74987 being actively exploited?
There are no public reports of exploitation of CVE-2026-74987 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-74987?
Vendor information indicates the issue affected recent Firefox releases and that fixes were released in Firefox 154 and corresponding ESR and Thunderbird updates.
Does CVE-2026-74987 require authentication?
No — the vulnerability can be reached remotely without authentication or user interaction.
What can an attacker do with CVE-2026-74987?
The memory-corruption bug can allow an attacker to execute arbitrary code, crash the browser, or otherwise compromise the affected Firefox process's confidentiality, integrity, and availability.
References
- nvd.nist.gov/vuln/detail/CVE-2026-74987
- cve.org/CVERecord?id=CVE-2026-74987
- bugzilla.mozilla.org/buglist.cgi?bug_id=1500946%2C1788109%2C2045379%2C2045380%2C2049339%2C2049393%2C2053580%2C2054662%2C2054665%2C2054673%2C2054785%2C2058645
- bugzilla.mozilla.org/buglist.cgi?bug_id=2048797%2C2050536%2C2053272%2C2053579%2C2057115%2C2057116%2C2057130%2C2057991%2C2057995%2C2058002%2C2058008%2C2058032%2C2058102%2C2058667
- bugzilla.mozilla.org/show_bug.cgi?id=2059424
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-76
- mozilla.org/security/advisories/mfsa2026-77
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-79
- mozilla.org/security/advisories/mfsa2026-80
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026