CVE-2026-74990: pre-auth remote code execution in Mozilla Firefox

Attackers can achieve remote code execution against Firefox by exploiting a memory-corruption flaw; this is tracked as CVE-2026-74990. The vulnerability is a CWE-119 memory-corruption issue with a CVSS 3.1 vector showing network attack (AV:N), no privileges (PR:N) and no user interaction (UI:N), indicating an attacker can trigger the flaw remotely. The supplied facts do not list a definitive set of affected Firefox releases or vendor-fixed versions; the vendor has not been reported as having a public patch available in the supplied data.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00715
CWE
CWE-119
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Act urgently: this is a critical, remote code execution flaw with no public patch reported in the provided facts, so inventory exposed Firefox installs and reduce their attack surface immediately.

What is CVE-2026-74990?

Attackers can achieve remote code execution against Firefox by exploiting a memory-corruption flaw; this is tracked as CVE-2026-74990. The vulnerability is a CWE-119 memory-corruption issue with a CVSS 3.1 vector showing network attack (AV:N), no privileges (PR:N) and no user interaction (UI:N), indicating an attacker can trigger the flaw remotely. The supplied facts do not list a definitive set of affected Firefox releases or vendor-fixed versions; the vendor has not been reported as having a public patch available in the supplied data.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Mozilla Firefox are affected?

BRANCHAFFECTEDFIXED

Is CVE-2026-74990 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-74990

  1. Follow Mozilla security advisories and apply vendor updates as soon as a patch is released.
  2. Limit exposure of Firefox instances to untrusted networks and content while a patch is unavailable.
  3. Monitor endpoint and network logs for signs of exploitation and block known malicious payloads where possible.
  4. Apply vendor guidance and mitigations from Mozilla when published.

Frequently asked questions

Is CVE-2026-74990 being actively exploited?

There are no public reports of exploitation of CVE-2026-74990 as of 2026-09-29.

Which Firefox versions are affected by CVE-2026-74990?

The supplied facts do not provide a definitive list of affected Firefox releases; vendor-provided affected-and-fixed version details were not included in the provided data.

Is there a patch for CVE-2026-74990?

No public patch is reported in the supplied facts as of 2026-09-29; follow Mozilla for an official update and install fixes when they are released.

Does CVE-2026-74990 require authentication?

No; the CVSS vector in the provided data shows no privileges required and no user interaction, indicating exploitation can be performed remotely without authentication.

References