DIRAS TAKE
Treat this as urgent: the flaw can be triggered remotely with no authentication or user interaction, so reduce exposure of affected clients and apply vendor guidance as soon as fixes are published.
What is CVE-2026-75874?
A remote attacker can escape the sandbox in the Remote Settings Client component, allowing code to run outside expected confinement on Mozilla products (CVE-2026-75874). Specific affected releases are not listed in the supplied facts; third-party reports reference Firefox and Thunderbird components. The vulnerability is remotely reachable without authentication or user interaction, so an attacker only needs network access to target affected installations.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of Mozilla Firefox are affected?
| BRANCH | AFFECTED | FIXED |
|---|
Is CVE-2026-75874 being exploited?
There are no public reports of active exploitation as of 2026-09-29.
How to fix CVE-2026-75874
- Follow Mozilla's security advisories and apply vendor patches immediately when released.
- Limit network exposure of client installations and block unnecessary remote access to update/configuration endpoints.
- Increase logging and monitor for anomalous behavior from the Remote Settings Client process.
- Temporary mitigations from Mozilla's guidance: disable or restrict the Remote Settings Client where possible until a patch is installed.
Frequently asked questions
Is CVE-2026-75874 being actively exploited?
No public reports of exploitation were available as of 2026-09-29.
Which Firefox versions are affected by CVE-2026-75874?
The supplied facts do not list specific affected versions; third-party reporting references the Remote Settings Client in Firefox and Thunderbird but does not provide an official affected-versions list here.
Is there a patch for CVE-2026-75874?
No patch was available in the provided facts as of 2026-09-29; monitor Mozilla security advisories for released fixes and install them promptly.
Does CVE-2026-75874 require authentication?
No, the vulnerability can be triggered without authentication or user interaction, so it is remotely exploitable with network access.
References
- nvd.nist.gov/vuln/detail/CVE-2026-75874
- cve.org/CVERecord?id=CVE-2026-75874
- bugzilla.mozilla.org/show_bug.cgi?id=2039972
- mozilla.org/security/advisories/mfsa2026-74
- mozilla.org/security/advisories/mfsa2026-78
- mozilla.org/security/advisories/mfsa2026-83
- mozilla.org/security/advisories/mfsa2026-84
- mozilla.org/security/advisories/mfsa2026-85
- mozilla.org/security/advisories/mfsa2026-87
- mozilla.org/security/advisories/mfsa2026-88
- All Mozilla CVEs on CVE Radar
- CVEs published in September 2026