DIRAS TAKE
Act urgently: this is a critical, remote code execution flaw with no public patch reported in the provided facts, so inventory exposed Firefox installs and reduce their attack surface immediately.
What is CVE-2026-74990?
Attackers can achieve remote code execution against Firefox by exploiting a memory-corruption flaw; this is tracked as CVE-2026-74990. The vulnerability is a CWE-119 memory-corruption issue with a CVSS 3.1 vector showing network attack (AV:N), no privileges (PR:N) and no user interaction (UI:N), indicating an attacker can trigger the flaw remotely. The supplied facts do not list a definitive set of affected Firefox releases or vendor-fixed versions; the vendor has not been reported as having a public patch available in the supplied data.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-74990 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-74990
- Follow Mozilla security advisories and apply vendor updates as soon as a patch is released.
- Limit exposure of Firefox instances to untrusted networks and content while a patch is unavailable.
- Monitor endpoint and network logs for signs of exploitation and block known malicious payloads where possible.
- Apply vendor guidance and mitigations from Mozilla when published.
Frequently asked questions
Is CVE-2026-74990 being actively exploited?
There are no public reports of exploitation of CVE-2026-74990 as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-74990?
The supplied facts do not provide a definitive list of affected Firefox releases; vendor-provided affected-and-fixed version details were not included in the provided data.
Is there a patch for CVE-2026-74990?
No public patch is reported in the supplied facts as of 2026-09-29; follow Mozilla for an official update and install fixes when they are released.
Does CVE-2026-74990 require authentication?
No; the CVSS vector in the provided data shows no privileges required and no user interaction, indicating exploitation can be performed remotely without authentication.
References
- nvd.nist.gov/vuln/detail/CVE-2026-74990
- cve.org/CVERecord?id=CVE-2026-74990
- bugzilla.mozilla.org/buglist.cgi?bug_id=2045762%2C2052401%2C2058208
- bugzilla.mozilla.org/buglist.cgi?bug_id=2045774%2C2048490%2C2050864%2C2053159%2C2053260%2C2053261%2C2053582%2C2053599%2C2053607%2C2053608%2C2053853%2C2054626%2C2054627%2C2054635%2C2054677%2C2054740%2C2054832%2C2056792%2C2057098%2C2057100%2C2057101%2C2057103%2C2057117%2C2057118%2C2058048%2C2058049%2C2058622%2C2058623%2C2058665%2C2058666%2C2059121%2C2059164%2C2059188
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-75
- mozilla.org/security/advisories/mfsa2026-76
- mozilla.org/security/advisories/mfsa2026-77
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-79
- mozilla.org/security/advisories/mfsa2026-80
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026