CVE-2026-74988: pre-auth remote code execution in Mozilla Firefox

Remote attackers can trigger memory-corruption in Mozilla Firefox and potentially execute arbitrary code on affected installations; this issue is tracked as CVE-2026-74988. The provided data does not list specific Firefox release numbers that are affected. The vulnerability is remote and requires only network access — no privileges or user interaction are required according to the supplied CVSS vector (AV:N/PR:N/UI:N).

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00609
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as high priority: the CVSS score is critical (9.8) and no vendor patch is listed in the provided data, so limit exposure and prepare to update as soon as Mozilla publishes fixes.

What is CVE-2026-74988?

Remote attackers can trigger memory-corruption in Mozilla Firefox and potentially execute arbitrary code on affected installations; this issue is tracked as CVE-2026-74988. The provided data does not list specific Firefox release numbers that are affected. The vulnerability is remote and requires only network access — no privileges or user interaction are required according to the supplied CVSS vector (AV:N/PR:N/UI:N).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74988 being exploited?

There are no public reports of exploitation as of 2026-09-29 and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog; public exploit code is not available in the provided data.

How to fix CVE-2026-74988

  1. Check Mozilla’s official security advisory and apply vendor updates as soon as they are released.
  2. Restrict Firefox access from untrusted networks and block unneeded inbound connections to reduce exposure.
  3. Monitor endpoint and network logs for crashes, unexpected process activity, or indicators of memory corruption.
  4. Implement host-based mitigations such as sandboxing, strong exploit mitigations, and up-to-date intrusion detection rules.

Frequently asked questions

Is CVE-2026-74988 being actively exploited?

No public reports of active exploitation are available as of 2026-09-29, and it is not listed in the CISA Known Exploited Vulnerabilities catalog in the provided data.

Which Firefox versions are affected by CVE-2026-74988?

The provided facts do not include a list of specific affected Firefox versions; consult Mozilla’s official advisory for exact version details when available.

Is there a patch for CVE-2026-74988?

No patch is listed in the provided data; watch Mozilla’s security advisories and apply the vendor’s updates when they are published.

Does CVE-2026-74988 require authentication?

No; according to the supplied CVSS vector the issue does not require authentication or user interaction and can be triggered remotely over the network.

References