CVE-2026-74989: pre-auth remote code execution in Mozilla Firefox

A remote attacker can cause memory corruption and achieve remote code execution in Mozilla Firefox via a vulnerability tracked as CVE-2026-74989. The weakness is classified as CWE-119 (memory safety) and the CVSSv3.1 vector indicates no privileges or user interaction are required. Vendor-stated affected-version details are not provided in the supplied facts; an attacker only needs to reach a vulnerable Firefox instance to exploit the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0057
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: the flaw is rated critical (CVSS 9.8) and no patch is listed in the provided facts, so immediately apply mitigations and prepare to deploy vendor updates when released.

What is CVE-2026-74989?

A remote attacker can cause memory corruption and achieve remote code execution in Mozilla Firefox via a vulnerability tracked as CVE-2026-74989. The weakness is classified as CWE-119 (memory safety) and the CVSSv3.1 vector indicates no privileges or user interaction are required. Vendor-stated affected-version details are not provided in the supplied facts; an attacker only needs to reach a vulnerable Firefox instance to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74989 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-74989

  1. Isolate and limit Firefox access from untrusted networks and sites.
  2. Apply vendor guidance and install official updates as soon as Mozilla releases them.
  3. Harden hosts running Firefox: enable process sandboxing, least-privilege execution, and endpoint monitoring for crashes and suspicious child processes.
  4. Monitor logs and intrusion detection alerts for crashes or exploit indicators and block any suspected malicious payloads.

Frequently asked questions

Is CVE-2026-74989 being actively exploited?

There are no public reports of exploitation of CVE-2026-74989 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-74989?

The supplied facts do not list specific affected Firefox versions, so affected-version details are not available in this briefing.

Is there a patch for CVE-2026-74989?

No patch is listed in the provided facts as of 2026-09-29; follow Mozilla guidance and apply updates when they become available.

Does CVE-2026-74989 require authentication?

No—according to the CVSS vector provided, CVE-2026-74989 does not require authentication or user interaction to be exploited.

References